5
CVSSv2

CVE-2013-2178

Published: 28/08/2013 Updated: 19/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The apache-auth.conf, apache-nohome.conf, apache-noscript.conf, and apache-overflows.conf files in Fail2ban prior to 0.8.10 do not properly validate log messages, which allows remote malicious users to block arbitrary IP addresses via certain messages in a request.

Vulnerable Product Search on Vulmon Subscribe to Product

fail2ban fail2ban 0.8.5

fail2ban fail2ban 0.8.4

fail2ban fail2ban 0.7.7

fail2ban fail2ban 0.7.6

fail2ban fail2ban 0.7.5

fail2ban fail2ban 0.6.0

fail2ban fail2ban 0.5.5

fail2ban fail2ban 0.4.0

fail2ban fail2ban 0.3.1

fail2ban fail2ban

fail2ban fail2ban 0.8.7.1

fail2ban fail2ban 0.8.1

fail2ban fail2ban 0.8.0

fail2ban fail2ban 0.7.2

fail2ban fail2ban 0.7.1

fail2ban fail2ban 0.5.2

fail2ban fail2ban 0.5.1

fail2ban fail2ban 0.1.1

fail2ban fail2ban 0.1.0

fail2ban fail2ban 0.8.7

fail2ban fail2ban 0.8.6

fail2ban fail2ban 0.7.9

fail2ban fail2ban 0.7.8

fail2ban fail2ban 0.7.0

fail2ban fail2ban 0.6.1

fail2ban fail2ban 0.5.0

fail2ban fail2ban 0.4.1

fail2ban fail2ban 0.8.8

fail2ban fail2ban 0.8.3

fail2ban fail2ban 0.8.2

fail2ban fail2ban 0.7.4

fail2ban fail2ban 0.7.3

fail2ban fail2ban 0.5.4

fail2ban fail2ban 0.5.3

fail2ban fail2ban 0.3.0

fail2ban fail2ban 0.1.2

Vendor Advisories

The apache-authconf, apache-nohomeconf, apache-noscriptconf, and apache-overflowsconf files in Fail2ban before 0810 do not properly validate log messages, which allows remote attackers to block arbitrary IP addresses via certain messages in a request ...