CVE-2013-2178
fail2ban - denial of service
EPSS 1.8%
描述
The apache-auth.conf, apache-nohome.conf, apache-noscript.conf, and apache-overflows.conf files in Fail2ban before 0.8.10 do not properly validate log messages, which allows remote attackers to block arbitrary IP addresses via certain messages in a request.
如何修補 CVE-2013-2178
要修補 CVE-2013-2178,請將受影響套件升級到下列已修補版本。
- Debian/fail2ban—升級至 0.8.10-1 或更新版本
- Debian/fail2ban—升級至 0.8.4-3+squeeze2 或更新版本
CVE-2013-2178 正在被利用嗎?
低 — EPSS 為 1.8%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 0.8.10-1
- from 0, < 0.8.4-3+squeeze2