PT-2006-1090 · Denyhosts · Denyhosts

Published

2006-12-06

·

Updated

2017-07-29

·

CVE-2006-6301

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: DenyHosts versions prior to 2.6
Description: The issue allows remote attackers to cause a denial of service by adding arbitrary IP addresses to the sshd log file. This can be achieved by logging in via ssh with a login name containing certain strings with an IP address, which is not properly handled by a regular expression. The vulnerability can lead to disruption of access to protected information and can be exploited remotely.
Recommendations: For DenyHosts versions prior to 2.6, update to version 2.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the sshd log file to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-09547
CVE-2006-6301

Affected Products

Denyhosts