DenyHosts Client Protocol Version Identification Remote Denial of Service Vulnerability

DenyHosts is prone to a remote denial-of-service vulnerability becaus the application fails to properly ensure the source of authentication-failure messages.

Successfully exploiting this issue allows remote attackers to add arbitrary IP addresses to the block list used by the application. Exploiting this allows attackers to deny further SSH network access to arbitrary IP addresses, denying service to legitimate users.

This issue is a variant of the vulnerability discussed in BID 21468 (DenyHosts Remote Denial of Service Vulnerability).


 

Privacy Statement
Copyright 2010, SecurityFocus