denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to cause a denial of service (incorrect block of IP addresses) via crafted login names.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Debian_linux | Debian | 6.0 (including) | 6.0 (including) |
Debian_linux | Debian | 7.0 (including) | 7.0 (including) |
Debian_linux | Debian | 7.1 (including) | 7.1 (including) |
Fedora | Fedoraproject | * | * |
Denyhosts | Ubuntu | lucid | * |
Denyhosts | Ubuntu | precise | * |
Denyhosts | Ubuntu | upstream | * |