Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3281

Опубликовано: 07 июл. 2015
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of previous requests) via a crafted request.

An implementation error related to the memory management of request and responses was found within HAProxy's buffer_slow_realign() function. An unauthenticated remote attacker could possibly use this flaw to leak certain memory buffer contents from a past request or session.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Enterprise 2haproxyNot affected
Red Hat Enterprise Linux 6haproxyFixedRHSA-2015:174108.09.2015
Red Hat Enterprise Linux 7haproxyFixedRHSA-2015:174108.09.2015
Red Hat OpenShift Enterprise 2.2haproxy15sideFixedRHSA-2015:266617.12.2015
Red Hat OpenShift Enterprise 2.2openshift-enterprise-upgradeFixedRHSA-2015:266617.12.2015
Red Hat OpenShift Enterprise 2.2openshift-origin-broker-utilFixedRHSA-2015:266617.12.2015
Red Hat OpenShift Enterprise 2.2openshift-origin-cartridge-haproxyFixedRHSA-2015:266617.12.2015
Red Hat OpenShift Enterprise 2.2openshift-origin-cartridge-jbosseapFixedRHSA-2015:266617.12.2015
Red Hat OpenShift Enterprise 2.2openshift-origin-cartridge-jbossewsFixedRHSA-2015:266617.12.2015
Red Hat OpenShift Enterprise 2.2openshift-origin-cartridge-pythonFixedRHSA-2015:266617.12.2015

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1239072haproxy: information leak in buffer_slow_realign()

EPSS

Процентиль: 27%
0.00094
Низкий

5 Medium

CVSS2

Связанные уязвимости

ubuntu
около 10 лет назад

The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of previous requests) via a crafted request.

nvd
около 10 лет назад

The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of previous requests) via a crafted request.

debian
около 10 лет назад

The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1. ...

github
больше 3 лет назад

The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of previous requests) via a crafted request.

oracle-oval
почти 10 лет назад

ELSA-2015-1741: haproxy security update (IMPORTANT)

EPSS

Процентиль: 27%
0.00094
Низкий

5 Medium

CVSS2