Buffer overflow in HAProxy 1.4 through 1.4.22 and 1.5-dev through 1.5-dev17, when HTTP keep-alive is enabled, using HTTP keywords in TCP inspection rules, and running with rewrite rules that appends to requests, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted pipelined HTTP requests that prevent request realignment from occurring.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade haproxy | Aug 30, 2017 | Apr 10, 2013 |
| Centos_linux | — | Upgrade haproxy | Dec 1, 2016 | Apr 10, 2013 |
| Debian | — | Upgrade haproxy | Jul 30, 2024 | Apr 10, 2013 |
| Gentoo Linux | — | Upgrade net-proxy/haproxy. | Oct 30, 2017 | Apr 10, 2013 |
| Ubuntu | — | Upgrade haproxy | Nov 8, 2024 | Apr 10, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub