Boletines de Vulnerabilidades

DSA-2979 fail2ban - security update


Información sobre el sistema

   
Software afectado Debian

Descripción

Two vulnerabilities were discovered in Fail2ban, a solution to ban hoststhat cause multiple authentication errors. When using Fail2ban to monitorPostfix or Cyrus IMAP logs, improper input validation in log parsingcould enable a remote attacker to trigger an IP ban on arbitraryaddresses, resulting in denial of service.

More info:

https://www.debian.org/security/2014/dsa-2979

Identificadores estándar

Propiedad Valor
CVE CVE-2013-7176 ,CVE-2013-7177 and DSA-2979.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-07-31

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT