A Debian bug report [1] noted that fail2ban would write temporary files insecurely. This could allow a local attacker to conduct a symlink attack and overwrite or append to files with root privileges. Fedora has this fixed already via fail2ban-0.8.4-notmp.patch (0.8.4-27), however EPEL is still vulnerable to this flaw. [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=544232
Created fail2ban tracking bugs for this issue Affects: epel-all [bug 718837]
*** This bug has been marked as a duplicate of bug 700763 ***