[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2826-1 denyhosts -- Remote denial of ssh service

ID: oval:org.secpod.oval:def:601173Date: (C)2014-01-08   (M)2022-10-10
Class: PATCHFamily: unix




Helmut Grohne discovered that denyhosts, a tool preventing SSH brute-force attacks, could be used to perform remote denial of service against the SSH daemon. Incorrectly specified regular expressions used to detect brute force attacks in authentication logs could be exploited by a malicious user to forge crafted login names in order to make denyhosts ban arbitrary IP addresses.

Platform:
Debian 7.0
Debian 6.0
Product:
denyhosts
Reference:
DSA-2826-1
CVE-2013-6890
CVE    1
CVE-2013-6890
CPE    4
cpe:/a:denyhosts:denyhosts
cpe:/o:debian:debian_linux:6.0
cpe:/o:debian:debian_linux:7.0
cpe:/o:debian:debian_linux:7.1
...

© SecPod Technologies