MGASA-2014-0176
Dashboard / Vulnerabilities / MGASA-2014-0176
Summary: Updated fail2ban packages fix security issues
Details: An update to fail2ban 0.8.13 has been released to fix security issues, amongst other bugfixes. fail2ban versions prior to 0.8.11 would allow a remote unauthenticated attacker to cause arbitrary IP addresses to be blocked by Fail2ban causing legitimate users to be blocked from accessing services protected by Fail2ban. These services are cyrus-imap (CVE-2013-7177) and postfix (CVE-2013-7176).
References: https://advisories.mageia.org/MGASA-2014-0176.html, https://github.com/fail2ban/fail2ban/releases, http://lists.opensuse.org/opensuse-updates/2014-03/msg00021.html, https://bugs.mageia.org/show_bug.cgi?id=11569
Affected packages
Package
Name: fail2ban
Purl: pkg:rpm/mageia/fail2ban?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
