haproxy: weak HMAC keys used to TLS session resumption after reload with rotated keys
Published May 9, 2019
5.9
MEDIUMCVSS 3.1
EPSS 1.25%
Description
HAProxy before 1.9.7 mishandles a reload with rotated keys, which triggers use of uninitialized, and very predictable, HMAC keys. This is related to an include/types/ssl_sock.h error.
Affected products
No data.
No data.
Red Hat Enterprise Linux 6
haproxy
Not affected
Red Hat Enterprise Linux 7
haproxy
Not affected
Red Hat Enterprise Linux 8
haproxy
Not affected
Red Hat OpenShift Container Platform 3.10
haproxy
Not affected
Red Hat OpenShift Container Platform 3.11
haproxy
Not affected
Red Hat OpenShift Container Platform 3.7
haproxy
Not affected
Red Hat OpenShift Container Platform 3.9
haproxy
Not affected
Red Hat OpenShift Container Platform 4
haproxy
Not affected
Red Hat OpenShift Enterprise 3
haproxy
Not affected
Red Hat Software Collections
rh-haproxy18-haproxy
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | haproxy | Not affected | n/a |
| Red Hat Enterprise Linux 7 | haproxy | Not affected | n/a |
| Red Hat Enterprise Linux 8 | haproxy | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.10 | haproxy | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | haproxy | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.7 | haproxy | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.9 | haproxy | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | haproxy | Not affected | n/a |
| Red Hat OpenShift Enterprise 3 | haproxy | Not affected | n/a |
| Red Hat Software Collections | rh-haproxy18-haproxy | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- http://git.haproxy.org/?p=haproxy.git%3Ba=commit%3Bh=8ef706502aa2000531d36e4ac56dbdc7c30f718d x_refsource_MISC
- https://access.redhat.com/security/cve/CVE-2019-11323 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1709229 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2019-11323
- https://www.cve.org/CVERecord?id=CVE-2019-11323
- https://www.mail-archive.com/haproxy%40formilux.org/msg33410.html x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| http://git.haproxy.org/?p=haproxy.git%3Ba=commit%3Bh=8ef706502aa2000531d36e4ac56dbdc7c30f718d | x_refsource_MISC | |
| https://access.redhat.com/security/cve/CVE-2019-11323 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1709229 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-11323 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-11323 | ||
| https://www.mail-archive.com/haproxy%40formilux.org/msg33410.html | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.