[<prev] [next>] [day] [month] [year] [list]
Message-Id: <E47CC180-3270-4525-91B3-E8A4A5FB3CF8@vndh.net>
Date: Tue, 11 Jun 2013 11:58:51 +0200
From: Krzysztof Katowicz-Kowalewski <vnd@...h.net>
To: "full-disclosure@...ts.grok.org.uk" <full-disclosure@...ts.grok.org.uk>
Subject: Fail2ban 0.8.9,
Denial of Service (Apache rules only)
Version 0.8.9 (latest) of Fail2ban allows to perform remote denial of service for arbitrary chosen IP address. Address listed on Fail2ban's whitelist are not affected. The vulnerability exists in Apache rules and it is caused by improper validation of a log file by regular expression. Malicious user can easily inject his own data to analyzed logs and deceive monitoring engine.
Affected files:
/filter.d/apache-auth.conf
/filter.d/apache-nohome.conf
/filter.d/apache-noscript.conf
/filter.d/apache-overflows.conf
Time frames:
01.06.2013 - Cyril Jaquier (contact section) has been informed about the vulnerability (no response)
08.06.2013 - The vulnerability has been released to the public.
More information, including proof of concept and patches is available here:
https://vndh.net/note:fail2ban-089-denial-service
Download attachment "signature.asc" of type "application/pgp-signature" (842 bytes)
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists