Description
Wazuh authd contains a heap-buffer overflow vulnerability that allows attackers to cause memory corruption and malformed heap data by sending specially crafted input. Attackers can exploit this vulnerability to trigger a denial of service condition, resulting in low impact on the availability of the authentication daemon.
Problem types
Product status
3.5.0 (semver)
4.3.10 (semver)
Credits
Reported by @vikman90; credited to @stasos24.
References
github.com/advisories/GHSA-grjq-p5fg-m24r
www.vulncheck.com/...ies/heap-buffer-overflow-in-wazuh-authd