[Bug 824710] New: Fail2Ban - Denial of Service in Apache rules
https://bugzilla.novell.com/show_bug.cgi?id=824710 https://bugzilla.novell.com/show_bug.cgi?id=824710#c0 Summary: Fail2Ban - Denial of Service in Apache rules Classification: openSUSE Product: openSUSE Factory Version: 13.1 Milestone 0 Platform: All OS/Version: openSUSE 12.3 Status: NEW Severity: Major Priority: P5 - None Component: Network AssignedTo: bnc-team-screening@forge.provo.novell.com ReportedBy: jweberhofer@weberhofer.at QAContact: qa-bugs@suse.de Found By: --- Blocker: --- User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:21.0) Gecko/20100101 Firefox/21.0 As also older versions are affected, the commit from https://github.com/fail2ban/fail2ban/pull/249 should be ported back to all supported versions OR all versions should be upgraded to the latest version. Johannes -------- Original Message -------- Subject: [Full-disclosure] Fail2ban 0.8.9, Denial of Service (Apache rules only) Date: Tue, 11 Jun 2013 11:58:51 +0200 From: Krzysztof Katowicz-Kowalewski <vnd@...> To: full-disclosure@... <full-disclosure@...> Version 0.8.9 (latest) of Fail2ban allows to perform remote denial of service for arbitrary chosen IP address. Address listed on Fail2ban's whitelist are not affected. The vulnerability exists in Apache rules and it is caused by improper validation of a log file by regular expression. Malicious user can easily inject his own data to analyzed logs and deceive monitoring engine. Affected files: /filter.d/apache-auth.conf /filter.d/apache-nohome.conf /filter.d/apache-noscript.conf /filter.d/apache-overflows.conf Time frames: 01.06.2013 - Cyril Jaquier (contact section) has been informed about the vulnerability (no response) 08.06.2013 - The vulnerability has been released to the public. More information, including proof of concept and patches is available here: https://vndh.net/note:fail2ban-089-denial-service Reproducible: Always -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=824710 https://bugzilla.novell.com/show_bug.cgi?id=824710#c Johannes Weberhofer <jweberhofer@weberhofer.at> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |NEEDINFO InfoProvider| |maintenance@opensuse.org -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=824710 https://bugzilla.novell.com/show_bug.cgi?id=824710#c1 Alexander Bergmann <abergmann@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEEDINFO |NEW CC| |abergmann@suse.com InfoProvider|maintenance@opensuse.org | AssignedTo|bnc-team-screening@forge.pr |lnussel@suse.com |ovo.novell.com | Summary|Fail2Ban - Denial of |VUL-0: fail2ban: DoS for |Service in Apache rules |arbitrary chosen IP | |addresses --- Comment #1 from Alexander Bergmann <abergmann@suse.com> 2013-06-13 08:20:06 UTC --- Only openSUSE is affected. openSUSE 12.2: based on 0.8.6 openSUSE 12.3: based on 0.8.8 The upstream fix can be found here: https://github.com/fail2ban/fail2ban/commit/6ccd57813cca617561fc67d2771361f3... -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=824710 https://bugzilla.novell.com/show_bug.cgi?id=824710#c2 Swamp Workflow Management <swamp@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Priority|P5 - None |P3 - Medium --- Comment #2 from Swamp Workflow Management <swamp@suse.de> 2013-06-13 16:00:10 UTC --- bugbot adjusting priority -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=824710 https://bugzilla.novell.com/show_bug.cgi?id=824710#c3 Alexander Bergmann <abergmann@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Summary|VUL-0: fail2ban: DoS for |VUL-0: fail2ban: |arbitrary chosen IP |CVE-2013-2178: DoS for |addresses |arbitrary chosen IP | |addresses Alias| |CVE-2013-2178 --- Comment #3 from Alexander Bergmann <abergmann@suse.com> 2013-06-14 00:27:49 UTC --- CVE-2013-2178 was assigned for this issue. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=824710 https://bugzilla.novell.com/show_bug.cgi?id=824710#c Ludwig Nussel <lnussel@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- AssignedTo|lnussel@suse.com |jweberhofer@weberhofer.at -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=824710 https://bugzilla.novell.com/show_bug.cgi?id=824710#c4 --- Comment #4 from Johannes Weberhofer <jweberhofer@weberhofer.at> 2013-06-19 15:45:34 CEST --- As I do not have a running 12.2 environment, I could not test the submitted fail2ban fix; The fixed package the 12.3 environment is running on one of my servers. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=824710 https://bugzilla.novell.com/show_bug.cgi?id=824710#c Swamp Workflow Management <swamp@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Status Whiteboard| |obs:running:1800:moderate -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=824710 https://bugzilla.novell.com/show_bug.cgi?id=824710#c5 Sebastian Krahmer <krahmer@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |RESOLVED Resolution| |FIXED --- Comment #5 from Sebastian Krahmer <krahmer@suse.com> 2013-07-02 09:15:21 UTC --- released -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=824710 https://bugzilla.novell.com/show_bug.cgi?id=824710#c6 --- Comment #6 from Swamp Workflow Management <swamp@suse.de> 2013-07-02 10:05:05 UTC --- openSUSE-SU-2013:1120-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 824710 CVE References: CVE-2013-2178 Sources used: openSUSE 12.3 (src): fail2ban-0.8.8-2.8.1 openSUSE 12.2 (src): fail2ban-0.8.6-2.9.1 -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=824710 https://bugzilla.novell.com/show_bug.cgi?id=824710#c7 --- Comment #7 from Swamp Workflow Management <swamp@suse.de> 2013-07-02 11:04:25 UTC --- openSUSE-SU-2013:1121-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 824710 CVE References: CVE-2013-2178 Sources used: openSUSE 11.4 (src): fail2ban-0.8.4-22.1 -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=824710 https://bugzilla.novell.com/show_bug.cgi?id=824710#c8 --- Comment #8 from Bernhard Wiedemann <bwiedemann@suse.com> 2013-07-02 16:00:09 CEST --- This is an autogenerated message for OBS integration: This bug (824710) was mentioned in https://build.opensuse.org/request/show/181757 Evergreen:11.2 / fail2ban -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=824710 https://bugzilla.novell.com/show_bug.cgi?id=824710#c9 Marcus Meissner <meissner@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |meissner@suse.com, | |security-team@suse.de --- Comment #9 from Marcus Meissner <meissner@suse.com> 2013-07-03 15:59:08 UTC --- CVE-2013-2178 -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=824710 https://bugzilla.novell.com/show_bug.cgi?id=824710#c10 --- Comment #10 from Bernhard Wiedemann <bwiedemann@suse.com> 2013-07-04 09:00:36 CEST --- This is an autogenerated message for OBS integration: This bug (824710) was mentioned in https://build.opensuse.org/request/show/181957 Evergreen:11.2 / fail2ban -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=824710 https://bugzilla.novell.com/show_bug.cgi?id=824710#c Swamp Workflow Management <swamp@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Status Whiteboard|obs:running:1800:moderate |obs:running:1800:moderate | |obs:running:2613:moderate -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=824710 https://bugzilla.novell.com/show_bug.cgi?id=824710#c11 --- Comment #11 from Swamp Workflow Management <swamp@suse.de> 2014-03-08 19:04:22 UTC --- openSUSE-SU-2014:0348-1: An update that fixes three vulnerabilities is now available. Category: security (moderate) Bug References: 824710,861503,861504 CVE References: CVE-2013-2178,CVE-2013-7176,CVE-2013-7177 Sources used: openSUSE 13.1 (src): fail2ban-0.8.12-2.5.1 openSUSE 12.3 (src): fail2ban-0.8.12-2.12.1 -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=824710 https://bugzilla.novell.com/show_bug.cgi?id=824710#c12 --- Comment #12 from Swamp Workflow Management <swamp@suse.de> 2014-04-08 19:04:22 UTC --- openSUSE-SU-2014:0493-1: An update that fixes three vulnerabilities is now available. Category: security (moderate) Bug References: 824710,861503,861504 CVE References: CVE-2013-2178,CVE-2013-7176,CVE-2013-7177 Sources used: openSUSE 11.4 (src): fail2ban-0.8.12-26.1 -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=824710 Swamp Workflow Management <swamp@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Whiteboard|obs:running:1800:moderate |obs:running:1800:moderate |obs:running:2613:moderate | -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=824710 Swamp Workflow Management <swamp@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Whiteboard|obs:running:1800:moderate | -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com