CVE Vulnerabilities

CVE-2009-0362

Improper Authentication

Published: Feb 13, 2009 | Modified: Feb 13, 2009
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

filter.d/wuftpd.conf in Fail2ban 0.8.3 uses an incorrect regular expression that allows remote attackers to cause a denial of service (forced authentication failures) via a crafted reverse-resolved DNS name (rhost) entry that contains a substring that is interpreted as an IP address, a different vulnerability than CVE-2007-4321.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Fail2ban Fail2ban 0.8.3 (including) 0.8.3 (including)
Fail2ban Ubuntu dapper *
Fail2ban Ubuntu gutsy *
Fail2ban Ubuntu hardy *
Fail2ban Ubuntu intrepid *
Fail2ban Ubuntu jaunty *
Fail2ban Ubuntu upstream *

Potential Mitigations

References