Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2006-6301
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-6301

Description:
DenyHosts 2.5 does not properly parse sshd logs file, which allows remote attackers to add arbitrary hosts to the /etc/hosts.deny file and cause a denial of service by adding arbitrary IP addresses to the sshd log file, as demonstrated by logging in to ssh using a login name containing certain strings with an IP address, which is not properly handled by a regular expression.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/30761

SAID
  Secunia Advisory: SA23236
  Secunia Advisory: SA23603

GENTOO
  http://security.gentoo.org/glsa/glsa-200701-01.xml

CONFIRM
  http://bugs.gentoo.org/show_bug.cgi?id=157163

BID
  21468


Return to the previous page.