CVE-2013-6890: Debian Linux
Medium severity, CVSS 5.0. EPSS: 8.9% chance of exploitation in the next 30 days.
denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to cause a denial of service (incorrect block of IP addresses) via crafted login names.
Affected products
- Debian Debian Linux: version 6.0 only; version 7.0 only; version 7.1 only
- Fedoraproject Fedora: any version
- Phil Schwartz Denyhosts: version 2.6 only
Published 2013-12-23. Last modified 2026-06-17.