An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14. Due to a missing check when validating DNS responses, remote attackers might be able read the 16 bytes corresponding to an AAAA record from the non-initialized part of the buffer, possibly accessing anything that was left on the stack, or even past the end of the 8193-byte buffer, depending on the value of accepted_payload_size.

Project Subscriptions

Vendors Products
Canonical Subscribe
Ubuntu Linux Subscribe
Haproxy Subscribe
Haproxy Subscribe
Openshift Subscribe
Openshift Container Platform Subscribe
Rhel Software Collections Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-3034-1 haproxy security update
EUVD EUVD EUVD-2018-12672 An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14. Due to a missing check when validating DNS responses, remote attackers might be able read the 16 bytes corresponding to an AAAA record from the non-initialized part of the buffer, possibly accessing anything that was left on the stack, or even past the end of the 8193-byte buffer, depending on the value of accepted_payload_size.
Ubuntu USN Ubuntu USN USN-3858-1 HAProxy vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T11:51:19.257Z

Reserved: 2018-12-12T00:00:00

Link: CVE-2018-20102

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-12-12T17:29:00.247

Modified: 2024-11-21T04:00:52.920

Link: CVE-2018-20102

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-12-12T00:00:00Z

Links: CVE-2018-20102 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses