CVE-2006-6301
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
DenyHosts 2.5 does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts to the /etc/hosts.deny file and cause a denial of service by adding arbitrary IP addresses to the sshd log file, as demonstrated by logging in via ssh with a login name containing certain strings with an IP address, which is not properly handled by a regular expression.
DenyHosts 2.5 no realiza un análisis sintáctico adecuado de los ficheros de log de sshd, lo cual permite a atacantes remotos añadir hosts de su elección al fichero /etc/hosts.deny y provocar una denegación de servicio añadiendo direcciones IP de su elección al fichero de log de sshd; como se ha demostrado accediendo por ssh utilizando un nombre de acceso que contiene ciertas cadenas con una dirección IP, lo cual no es tratado adecuadamente por una expresión regular.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-12-05 CVE Reserved
- 2006-12-06 CVE Published
- 2024-02-01 EPSS Updated
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/21468 | Vdb Entry | |
http://www.vupen.com/english/advisories/2006/4876 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/30761 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://bugs.gentoo.org/show_bug.cgi?id=157163 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/23236 | 2017-07-29 | |
http://secunia.com/advisories/23603 | 2017-07-29 | |
http://security.gentoo.org/glsa/glsa-200701-01.xml | 2017-07-29 |