Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2006-6301

EPSS 1.50% · P81
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2006-6301

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
DenyHosts 2.5 does not properly parse sshd log files, which allows remote attackers to add arbitrary hosts to the /etc/hosts.deny file and cause a denial of service by adding arbitrary IP addresses to the sshd log file, as demonstrated by logging in via ssh with a login name containing certain strings with an IP address, which is not properly handled by a regular expression.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
DenyHosts sshd日志文件远程拒绝服务漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
DenyHosts未正确解析sshd日志文件,远程攻击者可通过添加任意IP地址到sshd日志文件,如通过使用一个含有IP地址的特定字符串的登录名登录到ssh,让正则表达式无法正确处理,从而添加任意主机到/etc/hosts.deny文件并发起拒绝服务攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2006-6301

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2006-6301

登录查看更多情报信息。

Same Patch Batch · n/a · 2006-12-06 · 17 CVEs total

CVE-2006-6112LifeType 'class/和plugins/' 安全信息泄露漏洞
CVE-2006-6305Net-SNMP权限许可和访问控制漏洞
CVE-2006-6333Linux内核'IBMTR.C'远程拒绝服务漏洞
CVE-2006-6328TorrentFlux 'index.php'目录遍历漏洞
CVE-2006-6329TorrentFlux 'index.php'delfile参数文件删除漏洞
CVE-2006-6330TorrentFlux 'index.php'kill参数任意命令执行漏洞
CVE-2006-6331TorrentFlux 'metalnfo.php'任意命令执行漏洞
CVE-2006-5994Microsoft Word畸形字符串远程代码执行漏洞
CVE-2006-6308Symantec LiveState Agent 'shstart.exe'进程安全权限提升漏洞
CVE-2006-6309IBM Tivoli Storage Manager 多个数组索引错误
CVE-2006-6310Microsoft Internet Explorer Frame Src属性拒绝服务漏洞
CVE-2006-6311Internet Explorer CSS畸形宽度单元标记拒绝服务漏洞
CVE-2006-5855IBM Tivoli Storage Manager多个远程缓冲区溢出漏洞
CVE-2006-5856Adobe下载管理器畸形条目信息缓冲区溢出漏洞
CVE-2006-6302Fail2Ban 'hosts.deny'文件远程拒绝服务漏洞
CVE-2006-6303Yukihiro Matsumoto Ruby 'cgi.rb'库远程拒绝服务漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2006-6301

No comments yet


Leave a comment