Candidate: CVE-2013-7177 PublicDate: 2014-02-01 15:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7177 https://github.com/fail2ban/fail2ban/commit/bd175f026737d66e7110868fb50b3760ff75e087 http://www.kb.cert.org/vuls/id/686662 Description: config/filter.d/cyrus-imap.conf in the cyrus-imap filter in Fail2ban before 0.8.11 allows remote attackers to trigger the blocking of an arbitrary IP address via a crafted e-mail address that matches an improperly designed regular expression. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_fail2ban: upstream_fail2ban: released (0.8.11-1) lucid_fail2ban: ignored (reached end-of-life) precise_fail2ban: released (0.8.6-3wheezy3build0.12.04.1) quantal_fail2ban: ignored (reached end-of-life) saucy_fail2ban: ignored (reached end-of-life) trusty_fail2ban: not-affected (0.8.11-1) trusty/esm_fail2ban: not-affected (0.8.11-1) devel_fail2ban: not-affected (0.8.11-1)