--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2017-fc4bbe2631
2017-01-24 19:30:33.805038
--------------------------------------------------------------------------------

Name        : fail2ban
Product     : Fedora 24
Version     : 0.9.6
Release     : 2.fc24
URL         : http://fail2ban.sourceforge.net/
Summary     : Daemon to ban hosts that cause multiple authentication errors
Description :
Fail2Ban scans log files and bans IP addresses that makes too many password
failures. It updates firewall rules to reject the IP address. These rules can
be defined by the user. Fail2Ban can read multiple log files such as sshd or
Apache web server ones.

Fail2Ban is able to reduce the rate of incorrect authentications attempts
however it cannot eliminate the risk that weak authentication presents.
Configure services to use only two factor or public/private authentication
mechanisms if you really want to protect services.

This is a meta-package that will install the default configuration.  Other
sub-packages are available to install support for other actions and
configurations.

--------------------------------------------------------------------------------
Update Information:

Fix fail2ban-regex with journal broken in 0.9.6-1.  ----  Update to 0.9.6:  *
Misleading add resp. enable of (already available) jail in database, that
induced a subsequent error: last position of log file will be never retrieved
(gh-795) * Fixed a distribution related bug within
testReadStockJailConfForceEnabled   (e.g. test-cases faults on Fedora, see
gh-1353) * Fixed pythonic filters and test scripts (running via wrong python
version,   uses "fail2ban-python" now); * Fixed test case "testSetupInstallRoot"
for not default python version (also   using direct call, out of virtualenv); *
Fixed ambiguous wrong recognized date pattern resp. its optional parts (see
gh-1512); * FIPS compliant, use sha1 instead of md5 if it not allowed (see
gh-1540) * Monit config: scripting is not supported in path (gh-1556) *
`filter.d/apache-modsecurity.conf`     - Fixed for newer version (one space,
gh-1626), optimized: non-greedy catch-all       replaced for safer match,
unneeded catch-all anchoring removed, non-capturing * `filter.d/asterisk.conf`
- Fixed to match different asterisk log prefix (source file: method:) *
`filter.d/dovecot.conf`     - Fixed failregex ignores failures through some not
relevant info (gh-1623) * `filter.d/ignorecommands/apache-fakegooglebot`     -
Fixed error within apache-fakegooglebot, that will be called       with wrong
python version (gh-1506) * `filter.d/assp.conf`     - Extended failregex and
test cases to handle ASSP V1 and V2 (gh-1494) * `filter.d/postfix-sasl.conf`
- Allow for having no trailing space after 'failed:' (gh-1497) *
`filter.d/vsftpd.conf`     - Optional reason part in message after FAIL LOGIN
(gh-1543) * `filter.d/sendmail-reject.conf`     - removed mandatory double space
(if dns-host available, gh-1579) * filter.d/sshd.conf     - recognized "Failed
publickey for" (gh-1477);     - optimized failregex to match all of "Failed any-
method for ... from <HOST>" (gh-1479)     - eliminated possible complex
injections (on user-name resp. auth-info, see gh-1479)     - optional port part
after host (see gh-1533, gh-1581)  * New Actions:     - `action.d/npf.conf` for
NPF, the latest packet filter for NetBSD * New Filters:     - `filter.d/mongodb-
auth.conf` for MongoDB (document-oriented NoSQL database engine)       (gh-1586,
gh-1606 and gh-1607)  * DateTemplate regexp extended with the word-end boundary,
additionally to   word-start boundary * Introduces new command "fail2ban-
python", as automatically created symlink to   python executable, where fail2ban
currently installed (resp. its modules are located):     - allows to use the
same version, fail2ban currently running, e.g. in       external scripts just
via replace python with fail2ban-python:       ```diff       -#!/usr/bin/env
python       +#!/usr/bin/env fail2ban-python       ```     - always the same
pickle protocol     - the same (and also guaranteed available) fail2ban modules
- simplified stand-alone install, resp. stand-alone installation possibility
via setup (like gh-1487) is getting closer * Several test cases rewritten using
new methods assertIn, assertNotIn * New forward compatibility method
assertRaisesRegexp (normally python >= 2.7).   Methods assertIn, assertNotIn,
assertRaisesRegexp, assertLogged, assertNotLogged   are test covered now * Jail
configuration extended with new syntax to pass options to the backend (see
gh-1408),   examples:     - `backend =
systemd[journalpath=/run/log/journal/machine-1]`     - `backend =
systemd[journalfiles="/run/log/journal/machine-1/system.journal,
/run/log/journal/machine-1/user.journal"]`     - `backend =
systemd[journalflags=2]`  Fix sendmail-auth filter (bug #1329919)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1329919 - sendmail-auth.conf filter never matchs on failregex 
condition
        https://bugzilla.redhat.com/show_bug.cgi?id=1329919
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade fail2ban' at the command line.
For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to