DSA-2826-1 denyhosts -- remote denial of ssh service

Related Vulnerabilities: CVE-2013-6890  

Helmut Grohne discovered that denyhosts, a tool preventing SSH brute-force attacks, could be used to perform remote denial of service against the SSH daemon. Incorrectly specified regular expressions used to detect brute force attacks in authentication logs could be exploited by a malicious user to forge crafted login names in order to make denyhosts ban arbitrary IP addresses. For the oldstable distribution (squeeze), this problem has been fixed in version 2.6-7+deb6u2. For the stable distribution (wheezy), this problem has been fixed in version 2.6-10+deb7u2. For the testing distribution (jessie), this problem has been fixed in version 2.6-10.1. For the unstable distribution (sid), this problem has been fixed in version 2.6-10.1. We recommend that you upgrade your denyhosts packages.

Debian Security Advisory

DSA-2826-1 denyhosts -- remote denial of ssh service

Date Reported:
22 Dec 2013
Affected Packages:
denyhosts
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2013-6890.
More information:

Helmut Grohne discovered that denyhosts, a tool preventing SSH brute-force attacks, could be used to perform remote denial of service against the SSH daemon. Incorrectly specified regular expressions used to detect brute force attacks in authentication logs could be exploited by a malicious user to forge crafted login names in order to make denyhosts ban arbitrary IP addresses.

For the oldstable distribution (squeeze), this problem has been fixed in version 2.6-7+deb6u2.

For the stable distribution (wheezy), this problem has been fixed in version 2.6-10+deb7u2.

For the testing distribution (jessie), this problem has been fixed in version 2.6-10.1.

For the unstable distribution (sid), this problem has been fixed in version 2.6-10.1.

We recommend that you upgrade your denyhosts packages.