Lucene search

K
cve[email protected]CVE-2009-5023
HistoryJun 10, 2014 - 2:55 p.m.

CVE-2009-5023

2014-06-1014:55:08
CWE-59
web.nvd.nist.gov
26
fail2ban
cve-2009-5023
symlink attack
nvd

4.7 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:N/I:C/A:N

6.3 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

The (1) dshield.conf, (2) mail-buffered.conf, (3) mynetwatchman.conf, and (4) mynetwatchman.conf actions in action.d/ in Fail2ban before 0.8.5 allows local users to write to arbitrary files via a symlink attack on temporary files with predictable names, as demonstrated by /tmp/fail2ban-mail.txt.

Affected configurations

NVD
Node
fail2banfail2banRange0.8.4
OR
fail2banfail2banMatch0.1.0
OR
fail2banfail2banMatch0.1.1
OR
fail2banfail2banMatch0.1.2
OR
fail2banfail2banMatch0.3.0
OR
fail2banfail2banMatch0.3.1
OR
fail2banfail2banMatch0.4.0
OR
fail2banfail2banMatch0.4.1
OR
fail2banfail2banMatch0.5.0
OR
fail2banfail2banMatch0.5.1
OR
fail2banfail2banMatch0.5.2
OR
fail2banfail2banMatch0.5.3
OR
fail2banfail2banMatch0.5.4
OR
fail2banfail2banMatch0.5.5
OR
fail2banfail2banMatch0.6.0
OR
fail2banfail2banMatch0.6.1
OR
fail2banfail2banMatch0.7.0
OR
fail2banfail2banMatch0.7.1
OR
fail2banfail2banMatch0.7.2
OR
fail2banfail2banMatch0.7.3
OR
fail2banfail2banMatch0.7.4
OR
fail2banfail2banMatch0.7.5
OR
fail2banfail2banMatch0.7.6
OR
fail2banfail2banMatch0.7.7
OR
fail2banfail2banMatch0.7.8
OR
fail2banfail2banMatch0.7.9
OR
fail2banfail2banMatch0.8.0
OR
fail2banfail2banMatch0.8.1
OR
fail2banfail2banMatch0.8.2
OR
fail2banfail2banMatch0.8.3

4.7 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:N/I:C/A:N

6.3 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%