Fail2ban CVE-2012-5642 Arbitrary Log Content Injection Vulnerability
BID:56963
Info
Fail2ban CVE-2012-5642 Arbitrary Log Content Injection Vulnerability
| Bugtraq ID: | 56963 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-5642 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 17 2012 12:00AM |
| Updated: | Apr 13 2015 10:06PM |
| Credit: | NBS System security team |
| Vulnerable: |
Mandriva Business Server 1 X86 64 Mandriva Business Server 1 Cyril Jaquier Fail2Ban 0.8.7 Cyril Jaquier Fail2Ban 0.8.6 Cyril Jaquier Fail2Ban 0.8.5 Cyril Jaquier Fail2Ban 0.8.4 Cyril Jaquier Fail2Ban 0.8.3 |
| Not Vulnerable: |
Cyril Jaquier Fail2Ban 0.8.8 |
Discussion
Fail2ban CVE-2012-5642 Arbitrary Log Content Injection Vulnerability
Fail2ban is prone to a vulnerability that may allow a remote attacker to inject arbitrary content into the log file.
Successfully exploiting this issue allows an attacker to corrupt log files; other attacks are also possible.
Versions prior to Fail2ban 0.8.8 are vulnerable.
Fail2ban is prone to a vulnerability that may allow a remote attacker to inject arbitrary content into the log file.
Successfully exploiting this issue allows an attacker to corrupt log files; other attacks are also possible.
Versions prior to Fail2ban 0.8.8 are vulnerable.
Exploit / POC
Fail2ban CVE-2012-5642 Arbitrary Log Content Injection Vulnerability
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Fail2ban CVE-2012-5642 Arbitrary Log Content Injection Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Mandriva Business Server 1 X86 64
Solution:
Vendor updates are available. Please see the references for more information.
Mandriva Business Server 1 X86 64
-
Mandriva fail2ban-0.8.6-3.1.mbs1.noarch.rpm
http://www.mandriva.com/en/downloads/
References
Fail2ban CVE-2012-5642 Arbitrary Log Content Injection Vulnerability
References:
References: