SB2013071204 - Amazon Linux AMI update for fail2ban
Published: July 12, 2013
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2013-2178)
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
The apache-auth.conf, apache-nohome.conf, apache-noscript.conf, and apache-overflows.conf files in Fail2ban before 0.8.10 do not properly validate log messages, which allows remote attackers to block arbitrary IP addresses via certain messages in a request.
Remediation
Install update from vendor's website.