2024-07-14 02:06:08 +00:00

108 lines
3.4 KiB
JSON

{
"id": "CVE-2007-4323",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-08-14T00:17:00.000",
"lastModified": "2017-07-29T01:32:51.207",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "DenyHosts 2.6 does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts to the /etc/hosts.deny file and cause a denial of service by adding arbitrary IP addresses to the sshd log file, as demonstrated by logging in via ssh with a client protocol version identification containing an IP address string, a different vector than CVE-2006-6301."
},
{
"lang": "es",
"value": "DenyHosts 2.6 no analiza adecuadamente archivos de registro de sshd, lo cual permite a atacantes remotos a\u00f1adir anfitriones de su elecci\u00f3n al archivo /etc/hosts.deny y provocar una denegaci\u00f3n de servicio a\u00f1adiendo direcciones IP de su elecci\u00f3n al archivo de registro de sshd, como se ha demostrado accediendo mediante ssh con una identificacion de versi\u00f3n de protocolo de cliente que contiene una cadena de direcci\u00f3n IP, un vector diferente de CVE-2006-6301."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 6.8
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:denyhosts:denyhosts:2.6:*:*:*:*:*:*:*",
"matchCriteriaId": "672AF5F3-AAAD-4F43-A83D-F5F81AD1DBA8"
}
]
}
]
}
],
"references": [
{
"url": "http://bugs.gentoo.org/show_bug.cgi?id=181213",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/42482",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/27254",
"source": "cve@mitre.org"
},
{
"url": "http://security.gentoo.org/glsa/glsa-200710-14.xml",
"source": "cve@mitre.org"
},
{
"url": "http://www.ossec.net/en/attacking-loganalysis.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/26061",
"source": "cve@mitre.org"
},
{
"url": "https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=244943",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/37199",
"source": "cve@mitre.org"
}
]
}