Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14241

Опубликовано: 22 июл. 2019
Источник: redhat
CVSS3: 7.5
EPSS Средний

Описание

HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors related to htx_manage_client_side_cookies in proto_htx.c.

A flaw was found in HAProxy versions 2.0.0 through 2.0.2 and 1.9.0 through 1.9.8. An attacker can cause a denial of service via vectors related to htx_manage_client_side_cookies in proto_htx.c. The highest threat from this vulnerability is to system availability.

Отчет

Red Hat Enterprise Linux, Red Hat Software Collections, and Red Hat OpenStack Platform did not package these versions and are therefore not vulnerable to this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6haproxyNot affected
Red Hat Enterprise Linux 7haproxyNot affected
Red Hat Enterprise Linux 8haproxyNot affected
Red Hat OpenShift Container Platform 3.10haproxyNot affected
Red Hat OpenShift Container Platform 3.11haproxyNot affected
Red Hat OpenShift Container Platform 3.9haproxyNot affected
Red Hat OpenShift Container Platform 4haproxyNot affected
Red Hat OpenStack Platform 13 (Queens)rhosp13/openstack-haproxyNot affected
Red Hat OpenStack Platform 14 (Rocky)openstack-haproxy-containerNot affected
Red Hat Software Collectionsrh-haproxy18-haproxyNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1733583haproxy: DoS via vectors realted to htx_manage_client_side_cookies in proto_htx.c

EPSS

Процентиль: 97%
0.37036
Средний

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors related to htx_manage_client_side_cookies in proto_htx.c.

CVSS3: 7.5
nvd
больше 6 лет назад

HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors related to htx_manage_client_side_cookies in proto_htx.c.

CVSS3: 7.5
debian
больше 6 лет назад

HAProxy through 2.0.2 allows attackers to cause a denial of service (h ...

suse-cvrf
около 6 лет назад

Security update for haproxy

suse-cvrf
около 6 лет назад

Security update for haproxy

EPSS

Процентиль: 97%
0.37036
Средний

7.5 High

CVSS3