LWN.net Logo

denyhosts: denial of service

Package(s):denyhosts CVE #(s):CVE-2007-4323
Created:October 15, 2007 Updated:October 17, 2007
Description: DenyHosts 2.6 does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts to the /etc/hosts.deny file and cause a denial of service by adding arbitrary IP addresses to the sshd log file, as demonstrated by logging in via ssh with a client protocol version identification containing an IP address string, a different vector than CVE-2006-6301.
Alerts:
Gentoo 200710-14 2007-10-13

(Log in to post comments)

denyhosts: denial of service

Posted Oct 18, 2007 1:05 UTC (Thu) by epithumia (subscriber, #23370) [Link]

Fedora fixed this some time ago; for whatever reason this was reported months ago but was not
assigned a CVE number until recently.

https://admin.fedoraproject.org/updates/F7/FEDORA-2007-0589

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds