Lucene search

K
centosCentOS ProjectCESA-2013:0868
HistoryMay 29, 2013 - 8:24 a.m.

haproxy security update

2013-05-2908:24:29
CentOS Project
lists.centos.org
46

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

EPSS

0.086

Percentile

94.5%

CentOS Errata and Security Advisory CESA-2013:0868

HAProxy provides high availability, load balancing, and proxying for TCP
and HTTP-based applications.

A buffer overflow flaw was found in the way HAProxy handled pipelined HTTP
requests. A remote attacker could send pipelined HTTP requests that would
cause HAProxy to crash or, potentially, execute arbitrary code with the
privileges of the user running HAProxy. This issue only affected systems
using all of the following combined configuration options: HTTP keep alive
enabled, HTTP keywords in TCP inspection rules, and request appending
rules. (CVE-2013-1912)

Red Hat would like to thank Willy Tarreau of HAProxy upstream for reporting
this issue. Upstream acknowledges Yves Lafon from the W3C as the original
reporter.

HAProxy is released as a Technology Preview in Red Hat Enterprise Linux 6.
More information about Red Hat Technology Previews is available at
https://access.redhat.com/support/offerings/techpreview/

All users of haproxy are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.

Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2013-May/081911.html

Affected packages:
haproxy

Upstream details at:
https://access.redhat.com/errata/RHSA-2013:0868

OSVersionArchitecturePackageVersionFilename
CentOS6i686haproxy< 1.4.22-4.el6_4haproxy-1.4.22-4.el6_4.i686.rpm
CentOS6x86_64haproxy< 1.4.22-4.el6_4haproxy-1.4.22-4.el6_4.x86_64.rpm

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

EPSS

0.086

Percentile

94.5%