Fail2ban 0.8.9, Denial of Service (Apache rules only)

2013-06-11 / 2013-06-15
Risk: Medium
Local: No
Remote: Yes
CWE: CWE-20


Ogólna skala CVSS: 5/10
Znaczenie: 2.9/10
Łatwość wykorzystania: 10/10
Wymagany dostęp: Zdalny
Złożoność ataku: Niska
Autoryzacja: Nie wymagana
Wpływ na poufność: Brak
Wpływ na integralność: Brak
Wpływ na dostępność: Częściowy

Version 0.8.9 (latest) of Fail2ban allows to perform remote denial of service for arbitrary chosen IP address. Address listed on Fail2ban's whitelist are not affected. The vulnerability exists in Apache rules and it is caused by improper validation of a log file by regular expression. Malicious user can easily inject his own data to analyzed logs and deceive monitoring engine. Affected files: /filter.d/apache-auth.conf /filter.d/apache-nohome.conf /filter.d/apache-noscript.conf /filter.d/apache-overflows.conf Time frames: 01.06.2013 - Cyril Jaquier (contact section) has been informed about the vulnerability (no response) 08.06.2013 - The vulnerability has been released to the public. More information, including proof of concept and patches is available here: https://vndh.net/note:fail2ban-089-denial-service

Referencje:

https://vndh.net/note:fail2ban-089-denial-service
http://seclists.org/oss-sec/2013/q2/557


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top