PT-2014-1858 · Haproxy+2 · Haproxy+2

Publicado

2014-09-24

·

Atualizado

2024-06-15

·

CVE-2014-6269

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions HAProxy versions 1.5-dev23 through 1.5.3 HAProxy version 1.5.2
Description The issue is caused by multiple integer overflows in the http request forward body function in proto http.c, which allows remote attackers to cause a denial of service (crash) via a large stream of data. This triggers a buffer overflow and an out-of-bounds read. The vulnerability can be exploited remotely, leading to a disruption in the availability of protected information.
Recommendations For HAProxy versions 1.5-dev23 through 1.5.3, update to version 1.5.4 or later. For HAProxy version 1.5.2, update to version 1.5.4 or later. As a temporary workaround, consider restricting access to the http request forward body function in proto http.c to minimize the risk of exploitation.

Exploit

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-06997
BDU:2015-06998
BDU:2015-09243
BDU:2015-09244
CESA-2014_1292
CVE-2014-6269
OPENSUSE-SU-2024:10114-1
RHSA-2014:1292
RHSA-2014_1292
SUSE-SU-2015:0660-1

Produtos afetados

Centos
Haproxy
Red Hat