PT-2007-6700 · Openssh+1 · Openssh+1

Publicado

2007-10-30

·

Atualizado

2008-11-15

·

CVE-2007-5715

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions DenyHosts version 2.6
Description The issue arises from DenyHosts 2.6 processing OpenSSH sshd log messages with an incorrect regular expression, potentially allowing remote attackers to bypass detection when making invalid login attempts with a username not listed in AllowUsers. This could be achieved by using a username such as 'root' that is not present in the AllowUsers configuration.
Recommendations For DenyHosts version 2.6, consider updating the regular expression used to process OpenSSH sshd log messages to correctly match IP addresses and improve detection of invalid login attempts. As a temporary workaround, closely monitor login attempts and manually block suspicious IP addresses to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-5715

Produtos afetados

Denyhosts
Openssh