A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade haproxy | Jul 30, 2024 | Sep 21, 2018 |
| Redhat Openshift | — | Upgrade atomic-openshiftUpgrade golang-github-prometheus-node_exporterUpgrade atomic-openshift-dockerregistryUpgrade openshift-ansibleUpgrade haproxyUpgrade atomic-openshift-web-consoleUpgrade rubygem-ffi | Mar 12, 2019 | Sep 20, 2018 |
| Suse | — | Upgrade haproxy | Oct 24, 2018 | Sep 21, 2018 |
| Ubuntu | — | Upgrade haproxy | Oct 12, 2018 | Sep 21, 2018 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Sep 21, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub