An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14. Due to a missing check when validating DNS responses, remote attackers might be able read the 16 bytes corresponding to an AAAA record from the non-initialized part of the buffer, possibly accessing anything that was left on the stack, or even past the end of the 8193-byte buffer, depending on the value of accepted_payload_size.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade haproxy2-debuginfoUpgrade haproxy2 | Sep 28, 2023 | Dec 12, 2018 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Dec 12, 2018 |
| Debian | — | Upgrade haproxy | Jun 1, 2022 | Dec 12, 2018 |
| Huawei Euleros 2_0_sp8 | — | Upgrade haproxy | Jun 27, 2019 | Dec 12, 2018 |
| Redhat Openshift | — | Upgrade openshift-enterprise-autohealUpgrade jenkinsUpgrade atomic-openshift-node-problem-detectorUpgrade atomic-openshift-service-idlerUpgrade atomic-openshift-deschedulerUpgrade atomic-openshift-dockerregistryUpgrade atomic-openshift-metrics-serverUpgrade golang-github-prometheus-node_exporterUpgrade atomic-openshift-cluster-autoscalerUpgrade haproxyUpgrade golang-github-openshift-oauth-proxyUpgrade golang-github-prometheus-alertmanagerUpgrade jenkins-2-pluginsUpgrade openshift-ansibleUpgrade atomic-enterprise-service-catalogUpgrade atomic-openshiftUpgrade openshift-enterprise-cluster-capacityUpgrade golang-github-prometheus-prometheusUpgrade atomic-openshift-web-console | Mar 15, 2019 | Dec 12, 2018 |
| Suse | — | Upgrade haproxy | Jan 13, 2019 | Dec 12, 2018 |
| Ubuntu | — | Upgrade haproxy | Jan 23, 2019 | Dec 12, 2018 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 12, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub