Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-20615

Опубликовано: 21 мар. 2019
Источник: debian
EPSS Низкий

Описание

An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a crash. The processing of the PRIORITY flag in a HEADERS frame requires 5 extra bytes, and while these bytes are skipped, the total frame length was not re-checked to make sure they were present in the frame.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
haproxyfixed1.8.16-2package
haproxynot-affectedstretchpackage
haproxynot-affectedjessiepackage

Примечания

  • https://github.com/haproxy/haproxy/commit/a01f45e3ced23c799f6e78b5efdbd32198a75354

EPSS

Процентиль: 39%
0.00172
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 7 лет назад

An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a crash. The processing of the PRIORITY flag in a HEADERS frame requires 5 extra bytes, and while these bytes are skipped, the total frame length was not re-checked to make sure they were present in the frame.

CVSS3: 7.5
redhat
около 7 лет назад

An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a crash. The processing of the PRIORITY flag in a HEADERS frame requires 5 extra bytes, and while these bytes are skipped, the total frame length was not re-checked to make sure they were present in the frame.

CVSS3: 7.5
nvd
почти 7 лет назад

An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a crash. The processing of the PRIORITY flag in a HEADERS frame requires 5 extra bytes, and while these bytes are skipped, the total frame length was not re-checked to make sure they were present in the frame.

suse-cvrf
почти 7 лет назад

Security update for haproxy

suse-cvrf
около 7 лет назад

Security update for haproxy

EPSS

Процентиль: 39%
0.00172
Низкий