LWN.net Logo

Mageia alert MGASA-2012-0372 (fail2ban)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2012-0372: fail2ban-0.8.6-3.1.mga2 (2/core)
Date:  Mon, 31 Dec 2012 23:26:35 +0100
Message-ID:  <20121231222635.GA17438@valstar.mageia.org>
Archive-link:  Article, Thread

MGASA-2012-0372 Date: December 31st, 2012 Affected releases: 2 Description: Updated fail2ban package fixes security vulnerability: fail2ban before 0.8.8 didn't escape the content of <matches> (if used in custom action files), which could cause issues on the system running fail2ban as it scans log files, depending on what content is matched, since that content could contain arbitrary symbols. Updated Packages: fail2ban-0.8.6-3.1.mga2 References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5642 http://lists.fedoraproject.org/pipermail/package-announce... https://bugs.mageia.org/show_bug.cgi?id=8542 https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds