Loading
An issue was discovered in OSSEC 3.6.0. An uncontrolled recursion vulnerability in os_xml.c occurs when a large number of opening and closing XML tags is used. Because recursion is used in _ReadElem without restriction, an attacker can trigger a segmentation fault once unmapped memory is reached.
Use CWE-674, Ossec vendor hub and Ossec product page to widen CVE-2021-28040 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-8447, CVE-2020-8445 and CVE-2020-8444 for nearby disclosures in the same product family.