Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-32464

Опубликовано: 09 апр. 2025
Источник: debian
EPSS Низкий

Описание

HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow because of mishandling of the replacement of multiple short patterns with a longer one.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
haproxyfixed3.1.7-1experimentalpackage
haproxyfixed3.0.10-1package
haproxyfixed2.6.12-1+deb12u2bookwormpackage

Примечания

  • Introduced with: https://github.com/haproxy/haproxy/commit/07e1e3c93e74e44389545e457f0e1ff2e807cb9a (v2.2-dev3)

  • Fixed by: https://github.com/haproxy/haproxy/commit/3e3b9eebf871510aee36c3a3336faac2f38c9559 (v3.2-dev10)

  • Fixed by: https://git.haproxy.org/?p=haproxy-3.0.git;a=commit;h=ee1a64c2a04cc2cb38efb7e44f7ea7386d627bf6 (v3.0.10)

EPSS

Процентиль: 67%
0.0055
Низкий

Связанные уязвимости

CVSS3: 6.8
ubuntu
2 месяца назад

HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow because of mishandling of the replacement of multiple short patterns with a longer one.

CVSS3: 6.8
redhat
2 месяца назад

HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow because of mishandling of the replacement of multiple short patterns with a longer one.

CVSS3: 6.8
nvd
2 месяца назад

HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow because of mishandling of the replacement of multiple short patterns with a longer one.

CVSS3: 6.8
msrc
около 2 месяцев назад

Описание отсутствует

suse-cvrf
2 месяца назад

Security update for haproxy

EPSS

Процентиль: 67%
0.0055
Низкий