Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2006-6302
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-6302

Description:
fail2ban 0.7.4 and earlier does not properly parse sshd logs file, which allows remote attackers to add arbitrary hosts to the /etc/hosts.deny file and cause a denial of service by adding arbitrary IP addresses to the sshd log file, as demonstrated by logging in to ssh using a login name containing certain strings with an IP address.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/30739

SAID
  Secunia Advisory: SA23237
  Secunia Advisory: SA24184

GENTOO
  http://security.gentoo.org/glsa/glsa-200702-05.xml

CONFIRM
  http://bugs.gentoo.org/show_bug.cgi?id=157166

BID
  21469


Return to the previous page.