MEDIUM · 5.0

CVE-2013-6890

denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to cause a denial of service (incorrect block of IP addresses) via crafted login na...

Vulnerability Description

denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to cause a denial of service (incorrect block of IP addresses) via crafted login names.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
DebianDebian Linux6.0
FedoraprojectFedoraAll versions
Phil SchwartzDenyhosts2.6

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-6890?

CVE-2013-6890 is a vulnerability with a CVSS score of 5.0 (MEDIUM). denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to cause a denial of service (incorrect block of IP addresses) via crafted login na...

How severe is CVE-2013-6890?

CVE-2013-6890 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-6890?

Check the references section above for vendor advisories and patch information. Affected products include: Debian Debian Linux, Fedoraproject Fedora, Phil Schwartz Denyhosts.