Описание
Security update for haproxy
This update for haproxy fixes the following issues:
- CVE-2020-11100: Fixed an H2/HPAC vulnerability ch might have allowed arbitrary writes into a 32-bit relative address space (bsc#1168023).
This update was imported from the SUSE:SLE-15-SP1:Update update project.
Список пакетов
openSUSE Leap 15.1
haproxy-2.0.10+git0.ac198b92-lp151.2.9.1
Ссылки
- E-Mail link for openSUSE-SU-2020:0444-1
- SUSE Security Ratings
- SUSE Bug 1168023
- SUSE CVE CVE-2020-11100 page
Описание
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.
Затронутые продукты
openSUSE Leap 15.1:haproxy-2.0.10+git0.ac198b92-lp151.2.9.1
Ссылки
- CVE-2020-11100
- SUSE Bug 1168023