Fail2ban 'wuftpd.conf' Remote Denial of Service Vulnerability
BID:33734
Info
Fail2ban 'wuftpd.conf' Remote Denial of Service Vulnerability
| Bugtraq ID: | 33734 |
| Class: | Design Error |
| CVE: |
CVE-2009-0362 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 11 2009 12:00AM |
| Updated: | Apr 13 2015 09:42PM |
| Credit: | Chris Butler |
| Vulnerable: |
Cyril Jaquier Fail2Ban 0 |
| Not Vulnerable: | |
Discussion
Fail2ban 'wuftpd.conf' Remote Denial of Service Vulnerability
Fail2ban is prone to a remote denial-of-service vulnerability.
Successfully exploiting this issue allows remote attackers to add arbitrary IP addresses to the block list used by the application. This allows attackers to deny further network access to legitimate users.
Fail2ban is prone to a remote denial-of-service vulnerability.
Successfully exploiting this issue allows remote attackers to add arbitrary IP addresses to the block list used by the application. This allows attackers to deny further network access to legitimate users.
Exploit / POC
Fail2ban 'wuftpd.conf' Remote Denial of Service Vulnerability
Attackers use readily available network utilities to exploit this issue.
Attackers use readily available network utilities to exploit this issue.
Solution / Fix
Fail2ban 'wuftpd.conf' Remote Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Fail2ban 'wuftpd.conf' Remote Denial of Service Vulnerability
References:
References:
- Fail2ban Home Page (Cyril Jaquier)
- #514163 - ail2ban: allows DoS via construction of domain names starting with IP (Debian)