Summary
Multiple security issues have been found in HAProxy, a load-balancing reverse proxy:
CVE-2012-2942
Buffer overflow in the header capture code.
CVE-2013-1912
Buffer overflow in the HTTP keepalive code.
CVE-2013-2175
Denial of service in parsing HTTP headers.
Solution
For the oldstable distribution (squeeze), these problems have been fixed in version 1.4.8-1+squeeze1.
The stable distribution (wheezy) doesn't contain haproxy.
For the unstable distribution (sid), these problems have been fixed in version 1.4.24-1.
We recommend that you upgrade your haproxy packages.
Insight
HAProxy is a TCP/HTTP reverse proxy which is particularly suited for high availability environments. It features connection persistence through HTTP cookies, load balancing, header addition, modification, deletion both ways. It has request blocking capabilities and provides interface to display server status.
Affected
haproxy on Debian Linux
Detection
This check tests the installed software version using the apt package manager.
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2012-2942, CVE-2013-1912, CVE-2013-2175 -
CVSS Base Score: 5.1
AV:N/AC:H/Au:N/C:P/I:P/A:P
Related Vulnerabilities