MGASA-2014-0080

Source
https://advisories.mageia.org/MGASA-2014-0080.html
Import Source
https://advisories.mageia.org/MGASA-2014-0080.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0080
Upstream
  • CVE-2013-6890
Published
2014-02-17T00:22:31Z
Modified
2026-04-16T06:25:35.994198099Z
Summary
Updated denyhosts package fixes security vulnerability
Details

Helmut Grohne discovered that denyhosts, a tool preventing SSH brute-force attacks, could be used to perform remote denial of service against the SSH daemon. Incorrectly specified regular expressions used to detect brute force attacks in authentication logs could be exploited by a malicious user to forge crafted login names in order to make denyhosts ban arbitrary IP addresses (CVE-2013-6890).

This update also includes a fix for a regression introduced when fixing CVE-2013-6890.

References
Credits

Affected packages

Mageia:3 / denyhosts

Package

Name
denyhosts
Purl
pkg:rpm/mageia/denyhosts?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.6-4.4.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2014-0080.json"