Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Charlie Smurthwaite

#49497of 53,635
5Total CVSS
Vulnerabilities · 1
PT-2015-1626
5.0
2015-07-05
Haproxy · Haproxy · CVE-2015-3281
**Name of the Vulnerable Software and Affected Versions** HAProxy versions 1.5.x through 1.5.13 HAProxy version 1.6-dev **Description** The issue is related to the `buffer slow realign` function, which does not properly realign a buffer used for pending outgoing data. This allows remote attackers to obtain sensitive information, specifically uninitialized memory contents of previous requests, via a crafted request. **Recommendations** For HAProxy versions 1.5.x through 1.5.13, update to version 1.5.14 or later. For HAProxy version 1.6-dev, consider disabling the `buffer slow realign` function until a patch is available. As a temporary workaround, restrict access to sensitive information to minimize the risk of exploitation.