VYPR
High severity7.5NVD Advisory· Published Mar 5, 2021· Updated Jun 17, 2026

CVE-2021-28040

CVE-2021-28040

Description

An issue was discovered in OSSEC 3.6.0. An uncontrolled recursion vulnerability in os_xml.c occurs when a large number of opening and closing XML tags is used. Because recursion is used in _ReadElem without restriction, an attacker can trigger a segmentation fault once unmapped memory is reached.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • OSSEC/OSSECdescription
  • Ossec/Ossecllm-fuzzy2 versions
    =3.6.0+ 1 more
    • (no CPE)range: =3.6.0
    • cpe:2.3:a:ossec:ossec:3.6.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.