Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:31247
HistoryJul 19, 2021 - 12:16 a.m.

Remote Code Execution

2021-07-1900:16:39
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
fail2ban
remote code execution
vulnerability
mail-whois
mailutils package
arbitrary commands
unescaped sequences

EPSS

0.018

Percentile

88.1%

fail2ban is vulnerable to remote code execution. The mailing action mail-whois command mail from mailutils package used in mail actions like mail-whois can execute command allows an attacker to execute arbitrary commands due to unescaped sequences \n~ in foreign input.