source: http://www.securityfocus.com/bid/25117/info Fail2ban is prone to a remote denial-of-service vulnerability because the application fails to properly ensure the validity of authentication-failure messages. Successfully exploiting this issue allows remote attackers to add arbitrary IP addresses to the block list used by the application. This allows attackers to deny further network access to arbitrary IP addresses, denying service to legitimate users. Fail2ban 0.8.0 and prior versions are vulnerable to this issue. This issue may be demonstrated by connecting to an SSH server with 'nc', and sending the following string: ROOT LOGIN REFUSED hi FROM 18.104.22.168 where '22.214.171.124' is an IP address to be blocked.
Related ExploitsTrying to match CVEs (1): CVE-2007-4321
Trying to match OSVDBs (1): 42484
Other Possible E-DB Search Terms: Fail2ban 0.8, Fail