LWN.net Logo

fail2ban: denial of service

Package(s):fail2ban CVE #(s):CVE-2013-2178
Created:June 17, 2013 Updated:July 2, 2013
Description: From the Debian advisory:

Krzysztof Katowicz-Kowalewski discovered a vulnerability in fail2ban, a log monitoring and system which can act on attack by preventing hosts to connect to specified services using the local firewall.

When using fail2ban to monitor Apache logs, improper input validation in log parsing could enable a remote attacker to trigger an IP ban on arbitrary addresses, thus causing a denial of service.

Alerts:
Debian DSA-2708-1 2013-06-16
Fedora FEDORA-2013-10806 2013-06-28
Fedora FEDORA-2013-10830 2013-06-28
Mageia MGASA-2013-0192 2013-07-01
Mandriva MDVSA-2013:191 2013-07-02
openSUSE openSUSE-SU-2013:1120-1 2013-07-02
openSUSE openSUSE-SU-2013:1121-1 2013-07-02

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds