ALT-PU-2014-1952-1
Closed vulnerabilities
Modified: 2013-12-05
CVE-2012-5642
server/action.py in Fail2ban before 0.8.8 does not properly handle the content of the matches tag, which might allow remote attackers to trigger unsafe behavior in a custom action file via unspecified symbols in this content.
- https://github.com/fail2ban/fail2ban/commit/83109bc
- https://bugs.gentoo.org/show_bug.cgi?id=447572
- [oss-security] 20121217 Re: CVE request: fail2ban 0.8.8 fixes an input variable quoting flaw on
content - [fail2ban-users] 20121206 0.8.8 release
- https://bugzilla.redhat.com/show_bug.cgi?id=887914
- https://raw.github.com/fail2ban/fail2ban/master/ChangeLog
- openSUSE-SU-2013:0566
- openSUSE-SU-2013:0567
- MDVSA-2013:078
Modified: 2024-11-21
CVE-2013-2178
The apache-auth.conf, apache-nohome.conf, apache-noscript.conf, and apache-overflows.conf files in Fail2ban before 0.8.10 do not properly validate log messages, which allows remote attackers to block arbitrary IP addresses via certain messages in a request.
- openSUSE-SU-2014:0348
- openSUSE-SU-2014:0348
- DSA-2708
- DSA-2708
- [oss-security] 20130613 Re: Re: Fail2ban 0.8.9, Denial of Service (Apache rules only)
- [oss-security] 20130613 Re: Re: Fail2ban 0.8.9, Denial of Service (Apache rules only)
- oval:org.mitre.oval:def:17338
- oval:org.mitre.oval:def:17338
- https://raw.github.com/fail2ban/fail2ban/master/ChangeLog
- https://raw.github.com/fail2ban/fail2ban/master/ChangeLog
- https://vndh.net/note:fail2ban-089-denial-service
- https://vndh.net/note:fail2ban-089-denial-service
Modified: 2024-11-21
CVE-2013-7176
config/filter.d/postfix.conf in the postfix filter in Fail2ban before 0.8.11 allows remote attackers to trigger the blocking of an arbitrary IP address via a crafted e-mail address that matches an improperly designed regular expression.
Modified: 2024-11-21
CVE-2013-7177
config/filter.d/cyrus-imap.conf in the cyrus-imap filter in Fail2ban before 0.8.11 allows remote attackers to trigger the blocking of an arbitrary IP address via a crafted e-mail address that matches an improperly designed regular expression.
Closed bugs
Не работает с systemd