PT-2013-1252 · Haproxy+3 · Haproxy+3

David Torgerson

·

Publicado

2013-07-11

·

Atualizado

2024-06-15

·

CVE-2013-2175

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions HAProxy versions 1.4 through 1.4.23 HAProxy versions 1.5 through 1.5-dev18
Description The issue allows remote attackers to cause a denial of service, potentially leading to a crash, by exploiting the hdr ip or other hdr * functions with a negative occurrence count in HTTP headers. This is related to the MAX HDR HISTORY variable. Multiple vulnerabilities in the HAProxy package can lead to breaches of confidentiality, integrity, and availability of protected information, and can be exploited remotely.
Recommendations For HAProxy versions 1.4 through 1.4.23, update to version 1.4.24 or later to resolve the issue. For HAProxy versions 1.5 through 1.5-dev18, update to version 1.5-dev19 or later to resolve the issue. As a temporary workaround, consider restricting the use of hdr * functions with negative occurrence counts until a patch is available.

Correção

DoS

Buffer Overflow

RCE

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1710
BDU:2015-09733
CESA-2013_1120
CVE-2013-2175
DSA-2711-1
OPENSUSE-SU-2024:10114-1
RHSA-2013:1120
RHSA-2013:1204
RHSA-2013_1120

Produtos afetados

Alt Linux
Centos
Haproxy
Red Hat