← Back

CVE-2013-2178

nvd nist
Published: Aug 28, 2013Modified: Apr 29, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The apache-auth.conf, apache-nohome.conf, apache-noscript.conf, and apache-overflows.conf files in Fail2ban before 0.8.10 do not properly validate log messages, which allows remote attackers to block arbitrary IP addresses via certain messages in a request.

Affected (36)

Products: Fail2ban: Fail2ban
1 product
Fail2ban
Configuration A
36 vulnerable
Vulnerable SoftwareAffected Versions
Fail2ban
Up to 0.8.9
Version 0.1.0
Version 0.1.1
Version 0.1.2
Version 0.3.0
Version 0.3.1
Version 0.4.0
Version 0.4.1
Version 0.5.0
Version 0.5.1
Version 0.5.2
Version 0.5.3
Version 0.5.4
Version 0.5.5
Version 0.6.0
Version 0.6.1
Version 0.7.0
Version 0.7.1
Version 0.7.2
Version 0.7.3
Version 0.7.4
Version 0.7.5
Version 0.7.6
Version 0.7.7
Version 0.7.8
Version 0.7.9
Version 0.8.0
Version 0.8.1
Version 0.8.2
Version 0.8.3
Version 0.8.4
Version 0.8.5
Version 0.8.6
Version 0.8.7.1
Version 0.8.7
Version 0.8.8

Timeline

No history available yet.