CVE-2009-5023
Last modified
CVE-2009-5023 is a vulnerability of currently unknown severity. The (1) dshield.conf, (2) mail-buffered.conf, (3) mynetwatchman.conf, and (4) mynetwatchman.conf actions in action.d/ in Fail2ban before 0.8.5 allows local users to write to arbitrary files via a symlink attack on temporary files with predictable names, as demonstrated by /tmp/fail2ban-mail.txt.. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
The (1) dshield.conf, (2) mail-buffered.conf, (3) mynetwatchman.conf, and (4) mynetwatchman.conf actions in action.d/ in Fail2ban before 0.8.5 allows local users to write to arbitrary files via a symlink attack on temporary files with predictable names, as demonstrated by /tmp/fail2ban-mail.txt.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fail2ban | Fail2ban | <= 0.8.4 |
| Fail2ban | Fail2ban | 0.1.0 |
| Fail2ban | Fail2ban | 0.1.1 |
| Fail2ban | Fail2ban | 0.1.2 |
| Fail2ban | Fail2ban | 0.3.0 |
| Fail2ban | Fail2ban | 0.3.1 |
| Fail2ban | Fail2ban | 0.4.0 |
| Fail2ban | Fail2ban | 0.4.1 |
| Fail2ban | Fail2ban | 0.5.0 |
| Fail2ban | Fail2ban | 0.5.1 |
| Fail2ban | Fail2ban | 0.5.2 |
| Fail2ban | Fail2ban | 0.5.3 |
| Fail2ban | Fail2ban | 0.5.4 |
| Fail2ban | Fail2ban | 0.5.5 |
| Fail2ban | Fail2ban | 0.6.0 |
| Fail2ban | Fail2ban | 0.6.1 |
| Fail2ban | Fail2ban | 0.7.0 |
| Fail2ban | Fail2ban | 0.7.1 |
| Fail2ban | Fail2ban | 0.7.2 |
| Fail2ban | Fail2ban | 0.7.3 |
| Fail2ban | Fail2ban | 0.7.4 |
| Fail2ban | Fail2ban | 0.7.5 |
| Fail2ban | Fail2ban | 0.7.6 |
| Fail2ban | Fail2ban | 0.7.7 |
| Fail2ban | Fail2ban | 0.7.8 |
| Fail2ban | Fail2ban | 0.7.9 |
| Fail2ban | Fail2ban | 0.8.0 |
| Fail2ban | Fail2ban | 0.8.1 |
| Fail2ban | Fail2ban | 0.8.2 |
| Fail2ban | Fail2ban | 0.8.3 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-5023?
How severe is CVE-2009-5023?
How do I fix CVE-2009-5023?
Are you affected by CVE-2009-5023?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
