PT-2018-3535 · Haproxy+3 · Haproxy+3

Nathan Davison

·

Published

2018-12-12

·

Updated

2022-06-02

·

CVE-2018-20102

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: HAProxy versions through 1.8.14
Description: An out-of-bounds read issue in the dns validate dns response function in dns.c allows remote attackers to potentially read unauthorized data from the stack or past the end of the buffer, depending on the accepted payload size value. This could lead to unauthorized access to protected information.
Recommendations: For HAProxy versions through 1.8.14, update to a version that includes a fix for the out-of-bounds read issue in the dns validate dns response function. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1002
BDU:2020-03309
CVE-2018-20102
DLA-3034-1
OPENSUSE-SU-2019:0044-1
OPENSUSE-SU-2019_0044-1
RHSA-2019:0547
RHSA-2019:1436
SUSE-SU-2019:0061-1
SUSE-SU-2019_0061-1
USN-3858-1

Affected Products

Alt Linux
Haproxy
Suse
Ubuntu