Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-6269

Опубликовано: 05 авг. 2014
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

Multiple integer overflows in the http_request_forward_body function in proto_http.c in HAProxy 1.5-dev23 before 1.5.4 allow remote attackers to cause a denial of service (crash) via a large stream of data, which triggers a buffer overflow and an out-of-bounds read.

A buffer overflow flaw was discovered in the way HAProxy handled, under very specific conditions, data uploaded from a client. A remote attacker could possibly use this flaw to crash HAProxy.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Enterprise 1haproxyNot affected
Red Hat Enterprise Linux 6haproxyAffected
Red Hat OpenShift Enterprise 2haproxyNot affected
Red Hat OpenShift Enterprise 2haproxy15sideNot affected
Red Hat Enterprise Linux 7haproxyFixedRHSA-2014:129224.09.2014

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1136552haproxy: remote client denial of service vulnerability

EPSS

Процентиль: 32%
0.00124
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

Multiple integer overflows in the http_request_forward_body function in proto_http.c in HAProxy 1.5-dev23 before 1.5.4 allow remote attackers to cause a denial of service (crash) via a large stream of data, which triggers a buffer overflow and an out-of-bounds read.

nvd
почти 11 лет назад

Multiple integer overflows in the http_request_forward_body function in proto_http.c in HAProxy 1.5-dev23 before 1.5.4 allow remote attackers to cause a denial of service (crash) via a large stream of data, which triggers a buffer overflow and an out-of-bounds read.

debian
почти 11 лет назад

Multiple integer overflows in the http_request_forward_body function i ...

github
больше 3 лет назад

Multiple integer overflows in the http_request_forward_body function in proto_http.c in HAProxy 1.5-dev23 before 1.5.4 allow remote attackers to cause a denial of service (crash) via a large stream of data, which triggers a buffer overflow and an out-of-bounds read.

oracle-oval
почти 11 лет назад

ELSA-2014-1292: haproxy security update (MODERATE)

EPSS

Процентиль: 32%
0.00124
Низкий

4.3 Medium

CVSS2