Lucene search

K
cve[email protected]CVE-2007-5715
HistoryOct 30, 2007 - 7:46 p.m.

CVE-2007-5715

2007-10-3019:46:00
CWE-16
web.nvd.nist.gov
22
cve-2007-5715
denyhosts
openssh
sshd
allowusers
invalid login attempts
remote attackers

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.5 Medium

AI Score

Confidence

Low

0.035 Low

EPSS

Percentile

91.6%

DenyHosts 2.6 processes OpenSSH sshd “not listed in AllowUsers” log messages with an incorrect regular expression that does not match an IP address, which might allow remote attackers to avoid detection and blocking when making invalid login attempts with a username not present in AllowUsers, as demonstrated by the root username, a different vulnerability than CVE-2007-4323.

Affected configurations

NVD
Node
denyhostsdenyhostsMatch2.6
CPENameOperatorVersion
denyhosts:denyhostsdenyhostseq2.6

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.5 Medium

AI Score

Confidence

Low

0.035 Low

EPSS

Percentile

91.6%