LWN.net Logo

fail2ban: conflicts with selinux

Package(s):fail2ban CVE #(s):
Created:April 26, 2011 Updated:April 27, 2011
Description: From the Fedora advisory:

fail2ban used predictable /tmp files which a local user can allocate before fail2ban does. All tmp files have been moved to /var/lib/fail2ban. This also helps with selinux policies.

Another security related fix is that fail2ban defaulted to gamin which conflicts with selinux, so users had to typically choose between fail2ban and selinux. fail2ban now defaults to inotify (thanks to Jonathan Underwood).

Alerts:
Fedora FEDORA-2011-5151 2011-04-10
Fedora FEDORA-2011-5153 2011-04-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds