Bug 718836 - fail2ban: insecure usage of temporary files
Summary: fail2ban: insecure usage of temporary files
Keywords:
Status: CLOSED DUPLICATE of bug 700763
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 718837
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-07-04 22:40 UTC by Vincent Danen
Modified: 2019-09-29 12:45 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2011-07-05 03:48:07 UTC
Embargoed:


Attachments (Terms of Use)

Description Vincent Danen 2011-07-04 22:40:24 UTC
A Debian bug report [1] noted that fail2ban would write temporary files insecurely.  This could allow a local attacker to conduct a symlink attack and overwrite or append to files with root privileges.

Fedora has this fixed already via fail2ban-0.8.4-notmp.patch (0.8.4-27), however EPEL is still vulnerable to this flaw.

[1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=544232

Comment 1 Vincent Danen 2011-07-04 22:41:01 UTC
Created fail2ban tracking bugs for this issue

Affects: epel-all [bug 718837]

Comment 2 Vincent Danen 2011-07-05 03:48:07 UTC

*** This bug has been marked as a duplicate of bug 700763 ***


Note You need to log in before you can comment on or make changes to this bug.