PT-2018-3535 · Haproxy+3 · Haproxy+3
Nathan Davison
·
Published
2018-12-12
·
Updated
2022-06-02
·
CVE-2018-20102
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
HAProxy versions through 1.8.14
Description:
An out-of-bounds read issue in the
dns validate dns response function in dns.c allows remote attackers to potentially read unauthorized data from the stack or past the end of the buffer, depending on the accepted payload size value. This could lead to unauthorized access to protected information.Recommendations:
For HAProxy versions through 1.8.14, update to a version that includes a fix for the out-of-bounds read issue in the
dns validate dns response function.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Haproxy
Suse
Ubuntu