CVE-2007-2765
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
blockhosts.py in BlockHosts before 2.0.3 does not properly parse daemon log files, which allows remote attackers to add arbitrary deny entries to the /etc/hosts.allow file and cause a denial of service by adding arbitrary IP addresses to a daemon log file, as demonstrated by logging in through ssh using a login name containing certain strings with an IP address, which is not properly handled by a regular expression, a related issue to CVE-2006-6301.
El blockhosts.py en el BlockHosts anterior al 2.0.3 no analiza la sintásis correctamente de los ficheros de trazas del demonio, lo que permite a atacantes remotos añadir denegaciones de entradas de su elección en el fichero /etc/hosts.allow y provocar una denegación de servicio añadiendo direcciones IP de su elección en el fichero de trazas del demonio, como lo demostrado validándose en el sistema con ssh usando un nombre que contiene ciertas cadenas con direcciones IP, lo que no es manejado correctamente por las expresiones regulares. Relacionada con la vulnerabilidad CVE-2006-6301.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-05-18 CVE Reserved
- 2007-05-18 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://osvdb.org/36516 | Vdb Entry | |
http://secunia.com/advisories/25352 | Third Party Advisory | |
http://www.aczoom.com/tools/blockhosts/CHANGES | X_refsource_confirm | |
http://www.securityfocus.com/bid/24090 | Vdb Entry | |
http://www.vupen.com/english/advisories/2007/1906 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/34426 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ac Zoom Search vendor "Ac Zoom" | Blockhosts Search vendor "Ac Zoom" for product "Blockhosts" | <= 2.0.2 Search vendor "Ac Zoom" for product "Blockhosts" and version " <= 2.0.2" | - |
Affected
|