BlockHosts Remote Denial of Service Vulnerability

BlockHosts is prone to a remote denial-of-service vulnerability because the application fails to properly validate the source of authentication failure messages.

Successfully exploiting this issue allows remote attackers to add arbitrary IP addresses to the block list used by the application. This allows attackers to deny further SSH network access to arbitrary IP addresses, denying service to legitimate users.

Versions of BlockHosts prior to 2.0.3 are vulnerable to this issue.


 

Privacy Statement
Copyright 2010, SecurityFocus