CVE Vulnerabilities

CVE-2009-0362

Improper Authentication

Published: Feb 13, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

filter.d/wuftpd.conf in Fail2ban 0.8.3 uses an incorrect regular expression that allows remote attackers to cause a denial of service (forced authentication failures) via a crafted reverse-resolved DNS name (rhost) entry that contains a substring that is interpreted as an IP address, a different vulnerability than CVE-2007-4321.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Fail2banFail2ban0.8.3 (including)0.8.3 (including)
Fail2banUbuntudapper*
Fail2banUbuntugutsy*
Fail2banUbuntuhardy*
Fail2banUbuntuintrepid*
Fail2banUbuntujaunty*
Fail2banUbuntuupstream*

Potential Mitigations

References