MEDIUM
haproxy: rewrite rules flaw can lead to arbitrary code execution
Published Apr 10, 2013
5.1
MEDIUMCVSS 2.0
EPSS 5.57%
Description
Buffer overflow in HAProxy 1.4 through 1.4.22 and 1.5-dev through 1.5-dev17, when HTTP keep-alive is enabled, using HTTP keywords in TCP inspection rules, and running with rewrite rules that appends to requests, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted pipelined HTTP requests that prevent request realignment from occurring.
Affected products
No data.
No data.
RHEL 6 Version of OpenShift Enterprise
haproxy-0:1.4.22-5.el6op
Fixed · RHSA-2013:0729
Red Hat Enterprise Linux 6
haproxy-0:1.4.22-4.el6_4
Fixed · RHSA-2013:0868
| Product | Package | State | Advisory |
|---|---|---|---|
| RHEL 6 Version of OpenShift Enterprise | haproxy-0:1.4.22-5.el6op | Fixed | RHSA-2013:0729 |
| Red Hat Enterprise Linux 6 | haproxy-0:1.4.22-4.el6_4 | Fixed | RHSA-2013:0868 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (15)
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/103730.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/103770.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/103794.html vendor-advisoryx_refsource_FEDORA
- http://rhn.redhat.com/errata/RHSA-2013-0729.html vendor-advisoryx_refsource_REDHATVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0868.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/52725 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.debian.org/security/2013/dsa-2711 vendor-advisoryx_refsource_DEBIAN
- http://www.openwall.com/lists/oss-security/2013/04/03/1 mailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/58820 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-1800-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2013-1912 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=947581 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-1906 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-1912
- https://www.cve.org/CVERecord?id=CVE-2013-1912
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 10, 2013
Updated Aug 6, 2024
Reserved Feb 19, 2013
Link CVE-2013-1912
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2013-1906 Assigner redhat
Published Apr 10, 2013
Updated Aug 6, 2024
Exploited since n/a
Link EUVD-2013-1906