VDB
CVE-2006-6301
CVE-2006-6301
PUBLISHED
CVSS 5 MEDIUM
DenyHosts 2.5 does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts to the /etc/hosts.deny file and cause a denial of service by adding arbitrary IP addresses to the sshd log file, as demonstrated by logging in via ssh with a login name containing certain strings with an IP address, which is not properly handled by a regular expression.
EPSS 1.89% · 78.1th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
1.89%
78.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| denyhosts | denyhosts | 2.5 |
Timeline
- Dec 6, 2006 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 4, 2023 EPSS Score
- Jul 19, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
References
- denyhosts-log-files-dos(30761) vdb
- 21468 vdb
- http://bugs.gentoo.org/show_bug.cgi?id=157163 url
- ADV-2006-4876 vdb
- 23236 third-party-advisory
- 23603 third-party-advisory
- GLSA-200701-01 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2006-6301 advisory