PT-2012-6066 · Fail2Ban · Fail2Ban

Yarikoptic

·

Publicado

2012-12-31

·

Atualizado

2013-12-05

·

CVE-2012-5642

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Fail2ban versions prior to 0.8.8
Description The issue is related to the handling of the content of the matches tag in the server/action.py file. This might allow remote attackers to trigger unsafe behavior in a custom action file via unspecified symbols in this content.
Recommendations For versions prior to 0.8.8, update to version 0.8.8 or later to resolve the issue. As a temporary workaround, consider restricting access to custom action files to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2012-5642

Produtos afetados

Fail2Ban