Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-14645

Опубликовано: 21 сент. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 7.5

Описание

A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.

РелизСтатусПримечание
bionic

released

1.8.8-1ubuntu0.2
devel

not-affected

1.8.13-2
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected]
esm-infra/bionic

released

1.8.8-1ubuntu0.2
esm-infra/xenial

not-affected

precise/esm

DNE

trusty

not-affected

trusty/esm

DNE

trusty was not-affected
upstream

released

1.8.13-2
xenial

not-affected

Показывать по

EPSS

Процентиль: 45%
0.00225
Низкий

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
больше 7 лет назад

A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.

CVSS3: 7.5
nvd
больше 7 лет назад

A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.

CVSS3: 7.5
debian
больше 7 лет назад

A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, ...

CVSS3: 7.5
github
больше 3 лет назад

A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.

CVSS3: 7.5
fstec
больше 7 лет назад

Уязвимость HPACK декодера серверного программного обеспечения HAProxy, связанная с чтением за допустимыми границами буфера данных, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 45%
0.00225
Низкий

5 Medium

CVSS2

7.5 High

CVSS3