Bugzilla – Bug 690853
VUL-1: fail2ban: Use of insecure default temporary file
Last modified: 2019-03-26 15:30:36 UTC
Your friendly security team received the following report via oss-security. Please respond ASAP. The issue is public. ------------------------------------------------------------------------------ Date: Fri, 29 Apr 2011 13:02:04 +0200 From: Jan Lieskovsky <jlieskov@redhat.com> Subject: [oss-security] CVE Request -- fail2ban -- Use of insecure default temporary file when unbanning an IP (tmpfile = /tmp/fail2ban-mail.txt) Hello Josh, Steve, vendors, It was found that fail2ban IPs banner used insecure default temporary file when unbanning an IP address. A local attacker could use this flaw to conduct symlink attacks in order to gain access to sensitive information or potentially to overwrite arbitrary file on the system. References: [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=544232 [2] https://bugzilla.redhat.com/show_bug.cgi?id=700763 Patch applied by Debian distribution: [3] http://git.onerussian.com/?p=deb/fail2ban.git;a=commitdiff;h=ea7d352616b1e2232fcaa99b11807a86ce29ed8b Could you allocate a CVE id for this? (Note: It should CVE-2009-* identifier) Thank you & Regards, Jan. -- Jan iankko Lieskovsky / Red Hat Security Response Team
CVE-2009-5023
CVE-2009-5023: CVSS v2 Base Score: 3.3 (low) (AV:L/AC:M/Au:N/C:P/I:P/A:N)
after discussion with security-team only submitted to factory: rq80518
ludwig changed his mind :)
factory version submitted to 11.3 and 11.4
This is an autogenerated message for OBS integration: This bug (690853) was mentioned in https://build.opensuse.org/request/show/80518 Factory / fail2ban https://build.opensuse.org/request/show/80519 11.3 / fail2ban https://build.opensuse.org/request/show/80520 11.4 / fail2ban
The SWAMPID for this issue is 43740. This issue was rated as moderate. Please submit fixed packages until 2011-11-02. When done, please reassign the bug to security-team@suse.de. Patchinfo will be handled by security team.
Update released for: fail2ban Products: openSUSE 11.3 (i586) openSUSE 11.4 (i586)
done
This is an autogenerated message for OBS integration: This bug (690853) was mentioned in https://build.opensuse.org/request/show/688767 15.1 / fail2ban