PT-2018-3535 · Haproxy+3 · Haproxy+3

Nathan Davison

·

Publicado

2018-12-12

·

Atualizado

2022-06-02

·

CVE-2018-20102

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: HAProxy versions through 1.8.14
Description: An out-of-bounds read issue in the dns validate dns response function in dns.c allows remote attackers to potentially read unauthorized data from the stack or past the end of the buffer, depending on the accepted payload size value. This could lead to unauthorized access to protected information.
Recommendations: For HAProxy versions through 1.8.14, update to a version that includes a fix for the out-of-bounds read issue in the dns validate dns response function. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-1002
BDU:2020-03309
CVE-2018-20102
DLA-3034-1
OPENSUSE-SU-2019:0044-1
OPENSUSE-SU-2019_0044-1
RHSA-2019:0547
RHSA-2019:1436
SUSE-SU-2019:0061-1
SUSE-SU-2019_0061-1
USN-3858-1

Produtos afetados

Alt Linux
Haproxy
Suse
Ubuntu