LWN.net Logo

haproxy: code execution

Package(s):haproxy CVE #(s):CVE-2012-2942
Created:October 23, 2012 Updated:January 9, 2013
Description: From the CVE entry:

Buffer overflow in the trash buffer in the header capture functionality in HAProxy before 1.4.21, when global.tune.bufsize is set to a value greater than the default and header rewriting is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors.

Alerts:
Fedora FEDORA-2012-16033 2012-10-23
Fedora FEDORA-2012-16056 2012-10-23
Gentoo 201301-02 2013-01-08
Ubuntu USN-1800-1 2013-04-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds