Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-11323

Опубликовано: 14 апр. 2019
Источник: redhat
CVSS3: 5.9

Описание

HAProxy before 1.9.7 mishandles a reload with rotated keys, which triggers use of uninitialized, and very predictable, HMAC keys. This is related to an include/types/ssl_sock.h error.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6haproxyNot affected
Red Hat Enterprise Linux 7haproxyNot affected
Red Hat Enterprise Linux 8haproxyNot affected
Red Hat OpenShift Container Platform 3.10haproxyNot affected
Red Hat OpenShift Container Platform 3.11haproxyNot affected
Red Hat OpenShift Container Platform 3.7haproxyNot affected
Red Hat OpenShift Container Platform 3.9haproxyNot affected
Red Hat OpenShift Container Platform 4haproxyNot affected
Red Hat OpenShift Enterprise 3haproxyNot affected
Red Hat Software Collectionsrh-haproxy18-haproxyNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1709229haproxy: weak HMAC keys used to TLS session resumption after reload with rotated keys

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 6 лет назад

HAProxy before 1.9.7 mishandles a reload with rotated keys, which triggers use of uninitialized, and very predictable, HMAC keys. This is related to an include/types/ssl_sock.h error.

CVSS3: 5.9
nvd
больше 6 лет назад

HAProxy before 1.9.7 mishandles a reload with rotated keys, which triggers use of uninitialized, and very predictable, HMAC keys. This is related to an include/types/ssl_sock.h error.

CVSS3: 5.9
debian
больше 6 лет назад

HAProxy before 1.9.7 mishandles a reload with rotated keys, which trig ...

CVSS3: 5.9
github
больше 3 лет назад

HAProxy before 1.9.7 mishandles a reload with rotated keys, which triggers use of uninitialized, and very predictable, HMAC keys. This is related to an include/types/ssl_sock.h error.

5.9 Medium

CVSS3