Note:
This project will be discontinued after December 13, 2021. [more]
2018-09-21
A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.
Products | Ubuntu_linux, Haproxy, Enterprise_linux, Openshift, Openshift_container_platform |
Type | Out-of-bounds Read (CWE-125) |
First patch | - None (likely due to unavailable code) |
Links |
• https://access.redhat.com/errata/RHBA-2019:0028
• https://www.mail-archive.com/haproxy%40formilux.org/msg31253.html • https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14645 • https://usn.ubuntu.com/3780-1/ • https://access.redhat.com/errata/RHSA-2018:2882 |