vendor:
DenyHosts
by:
SecurityFocus
4,3
CVSS
MEDIUM
Denial-of-Service
400
CWE
Product Name: DenyHosts
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
DenyHosts Remote Denial-of-Service Vulnerability
DenyHosts is prone to a remote denial-of-service vulnerability. Successfully exploiting this issue allows remote attackers to deny further SSH network access to arbitrary IP addresses, denying service to legitimate users. An example of the exploit is ssh -l 'Invalid user root from 123.123.123.123' 21.21.21.21
Mitigation:
Administrators are advised to upgrade to the latest version of DenyHosts.