Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 8: 2021-0464 Critical: Fail2ban Remote Code Execution

mageia
Calendar Grey October 6, 2021
Dist Mageia Esm H88
Recent updates to fail2ban in Mageia tackle a critical vulnerability that could allow remote code execution. Discover more details.
fail2ban is a daemon to ban hosts that cause multiple authentication errors

Summary

fail2ban is a daemon to ban hosts that cause multiple authentication errors. In versions 0.9.7 and prior, 0.10.0 through 0.10.6, and 0.11.0 through 0.11.2, there is a vulnerability that leads to possible remote code execution in the mailing action mail-whois. Command `mail` from mailutils package used in mail actions like `mail-whois` can execute command if unescaped sequences (`\n~`) are available in "foreign" input (for instance in whois output). To exploit the vulnerability, an attacker would need to insert malicious characters into the response sent by the whois server, either via a MITM attack or by taking over a whois server. (CVE-2021-32749)

References

- https://bugs.mageia.org/show_bug.cgi?id=29469

-

- https://bugzilla.suse.com/show_bug.cgi?id=1188610

- https://github.com/fail2ban/fail2ban/security/advisories/GHSA-m985-3f3v-cwmm

- https://www.cve.org/CVERecord?id=CVE-2021-32749

Resolution

SRPMS

- 8/core/fail2ban-0.11.2-1.1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 06 Oct 2021
URL: https://advisories.mageia.org/MGASA-2021-0464.html
Type: security
CVE: CVE-2021-32749

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here