5

CVE-2014-6269

Exploit
Multiple integer overflows in the http_request_forward_body function in proto_http.c in HAProxy 1.5-dev23 before 1.5.4 allow remote attackers to cause a denial of service (crash) via a large stream of data, which triggers a buffer overflow and an out-of-bounds read.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Haproxy ≫ Haproxy Version 1.5 Update dev23
Haproxy ≫ Haproxy Version 1.5 Update dev24
Haproxy ≫ Haproxy Version 1.5 Update dev25
Haproxy ≫ Haproxy Version 1.5 Update dev26
Haproxy ≫ Haproxy Version 1.5.0
Haproxy ≫ Haproxy Version 1.5.1
Haproxy ≫ Haproxy Version 1.5.2
Haproxy ≫ Haproxy Version 1.5.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.81% 0.887
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://article.gmane.org/gmane.comp.web.haproxy/17726
Exploit
http://article.gmane.org/gmane.comp.web.haproxy/18097
http://git.haproxy.org/?p=haproxy-1.5.git%3Ba=commitdiff%3Bh=b4d05093bc89f71377230228007e69a1434c1a0c
http://rhn.redhat.com/errata/RHSA-2014-1292.html
http://secunia.com/advisories/59936
http://secunia.com/advisories/61507
http://www.openwall.com/lists/oss-security/2014/09/09/23