René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

83 lines
2.7 KiB
JSON

{
"id": "CVE-2007-5715",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-10-30T19:46:00.000",
"lastModified": "2008-11-15T07:01:56.750",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "DenyHosts 2.6 processes OpenSSH sshd \"not listed in AllowUsers\" log messages with an incorrect regular expression that does not match an IP address, which might allow remote attackers to avoid detection and blocking when making invalid login attempts with a username not present in AllowUsers, as demonstrated by the root username, a different vulnerability than CVE-2007-4323."
},
{
"lang": "es",
"value": "DenyHosts 2.6 procesa mensajes de registro (log) de OpenSSH sshd del tipo \"no listado en usuarios permitidos\" (not listed in AllowUsers) con una expresi\u00f3n regular incorrecta que no coincide con una direcci\u00f3n IP, lo cual podr\u00eda permitir a atacantes remotos evitar la detecci\u00f3n y el bloqueo cuando hacen intentos de acceso inv\u00e1lidos con un nombre de usuario no presente en AllowUsers, como se ha demostrado usando el nombre de usuario root, una vulnerabilidad diferente de CVE-2007-4323."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 4.3
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-16"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:denyhosts:denyhosts:2.6:*:*:*:*:*:*:*",
"matchCriteriaId": "672AF5F3-AAAD-4F43-A83D-F5F81AD1DBA8"
}
]
}
]
}
],
"references": [
{
"url": "http://bugs.gentoo.org/show_bug.cgi?id=181213",
"source": "cve@mitre.org"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=237449",
"source": "cve@mitre.org"
}
]
}