CVE-2012-5642
EPSS 1.6%
Description
server/action.py in Fail2ban before 0.8.8 does not properly handle the content of the matches tag, which might allow remote attackers to trigger unsafe behavior in a custom action file via unspecified symbols in this content.
How to fix CVE-2012-5642
To remediate CVE-2012-5642, upgrade the affected package to a fixed version below.
- Debian/fail2ban—upgrade to 0.8.6-3wheezy1 or later
Is CVE-2012-5642 being exploited?
Low — EPSS is 1.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.8.6-3wheezy1