CVE-2021-32749
Summary
| CVE | CVE-2021-32749 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-16 18:15:00 UTC |
| Updated | 2023-11-07 03:35:00 UTC |
| Description | fail2ban is a daemon to ban hosts that cause multiple authentication errors. In versions 0.9.7 and prior, 0.10.0 through 0.10.6, and 0.11.0 through 0.11.2, there is a vulnerability that leads to possible remote code execution in the mailing action mail-whois. Command `mail` from mailutils package used in mail actions like `mail-whois` can execute command if unescaped sequences (`\n~`) are available in "foreign" input (for instance in whois output). To exploit the vulnerability, an attacker would need to insert malicious characters into the response sent by the whois server, either via a MITM attack or by taking over a whois server. The issue is patched in versions 0.10.7 and 0.11.3. As a workaround, one may avoid the usage of action `mail-whois` or patch the vulnerability manually. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| GNU Mailutils: unexpected processsing of escape sequences (GLSA 202310-13) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] Fedora 35 Update: fail2ban-0.11.2-9.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 35 Update: fail2ban-0.11.2-9.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: fail2ban-0.11.2-9.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| fixed possible RCE vulnerability, unset escape variable (default tild… · fail2ban/fail2ban@410a6ce · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 34 Update: fail2ban-0.11.2-9.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Possible RCE vulnerability in mailing action using mailutils (mail-whois) · Advisory · fail2ban/fail2ban · GitHub |
CONFIRM |
github.com |
|
| fixed possible RCE vulnerability, unset escape variable (default tild… · fail2ban/fail2ban@2ed414e · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179503 Debian Security Update for fail2ban (CVE-2021-32749)
- 281997 Fedora Security Update for fail2ban (FEDORA-2021-0ab8f6a19a)
- 501956 Alpine Linux Security Update for fail2ban
- 502215 Alpine Linux Security Update for fail2ban
- 503920 Alpine Linux Security Update for fail2ban
- 690199 Free Berkeley Software Distribution (FreeBSD) Security Update for fail2ban (c848059a-318b-11ec-aa15-0800270512f4)
- 710773 Gentoo Linux GNU Mailutils unexpected processsing of escape sequences Vulnerability (GLSA 202310-13)
- 751147 OpenSUSE Security Update for fail2ban (openSUSE-SU-2021:1274-1)