Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The (1) dshield.conf, (2) mail-buffered.conf, (3) mynetwatchman.conf, and (4) mynetwatchman.conf actions in action.d/ in Fail2ban before 0.8.5 allows local users to write to arbitrary files via a symlink attack on temporary files with predictable names, as demonstrated by /tmp/fail2ban-mail.txt.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Fail2ban 本地权限提升漏洞
Vulnerability Description
Fail2ban是软件开发者Cyril Jaquier所研发的一套基于Python的IP自动屏蔽工具。该工具可对系统日志进行监视,发现异常IP信息自动调用防火墙进行屏蔽,并发送E-mail通知系统管理员。 Fail2ban 0.8.5之前版本的action.d/ URI中存在安全漏洞,该漏洞源于dshield,mail-buffered.conf,mynetwatchman,mynetwatchman操作使用不安全的临时文件。本地攻击者可通过对临时文件实施符号链接攻击利用该漏洞写任意文件。
CVSS Information
N/A
Vulnerability Type
N/A