5

CVE-2013-2175

HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows remote attackers to cause a denial of service (negative array index usage and crash) via an HTTP header with a certain number of values, related to the MAX_HDR_HISTORY variable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 6.0
Canonical ≫ Ubuntu Linux Version 12.04 Update - Edition lts
Canonical ≫ Ubuntu Linux Version 12.10
Canonical ≫ Ubuntu Linux Version 13.04
Haproxy ≫ Haproxy Version 1.4
Haproxy ≫ Haproxy Version 1.4.0
Haproxy ≫ Haproxy Version 1.4.1
Haproxy ≫ Haproxy Version 1.4.2
Haproxy ≫ Haproxy Version 1.4.3
Haproxy ≫ Haproxy Version 1.4.4
Haproxy ≫ Haproxy Version 1.4.5
Haproxy ≫ Haproxy Version 1.4.6
Haproxy ≫ Haproxy Version 1.4.7
Haproxy ≫ Haproxy Version 1.4.8
Haproxy ≫ Haproxy Version 1.4.9
Haproxy ≫ Haproxy Version 1.4.10
Haproxy ≫ Haproxy Version 1.4.11
Haproxy ≫ Haproxy Version 1.4.12
Haproxy ≫ Haproxy Version 1.4.13
Haproxy ≫ Haproxy Version 1.4.14
Haproxy ≫ Haproxy Version 1.4.15
Haproxy ≫ Haproxy Version 1.4.16
Haproxy ≫ Haproxy Version 1.4.17
Haproxy ≫ Haproxy Version 1.4.18
Haproxy ≫ Haproxy Version 1.4.19
Haproxy ≫ Haproxy Version 1.4.20
Haproxy ≫ Haproxy Version 1.4.21
Haproxy ≫ Haproxy Version 1.4.22
Haproxy ≫ Haproxy Version 1.4.23
Haproxy ≫ Haproxy Version 1.5 Update dev
Haproxy ≫ Haproxy Version 1.5 Update dev0
Haproxy ≫ Haproxy Version 1.5 Update dev1
Haproxy ≫ Haproxy Version 1.5 Update dev10
Haproxy ≫ Haproxy Version 1.5 Update dev11
Haproxy ≫ Haproxy Version 1.5 Update dev12
Haproxy ≫ Haproxy Version 1.5 Update dev13
Haproxy ≫ Haproxy Version 1.5 Update dev14
Haproxy ≫ Haproxy Version 1.5 Update dev15
Haproxy ≫ Haproxy Version 1.5 Update dev16
Haproxy ≫ Haproxy Version 1.5 Update dev17
Haproxy ≫ Haproxy Version 1.5 Update dev18
Haproxy ≫ Haproxy Version 1.5 Update dev2
Haproxy ≫ Haproxy Version 1.5 Update dev3
Haproxy ≫ Haproxy Version 1.5 Update dev4
Haproxy ≫ Haproxy Version 1.5 Update dev5
Haproxy ≫ Haproxy Version 1.5 Update dev6
Haproxy ≫ Haproxy Version 1.5 Update dev7
Haproxy ≫ Haproxy Version 1.5 Update dev8
Haproxy ≫ Haproxy Version 1.5 Update dev9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.52% 0.878
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

http://www.debian.org/security/2013/dsa-2711
Third Party Advisory
http://marc.info/?l=haproxy&m=137147915029705&w=2
Patch
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-1120.html
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-1204.html
Third Party Advisory
http://secunia.com/advisories/54344
http://www.ubuntu.com/usn/USN-1889-1
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=974259
Issue Tracking