Description
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-4649-1 | haproxy security update |
EUVD |
EUVD-2020-3458 | In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution. |
Ubuntu USN |
USN-4321-1 | HAProxy vulnerability |
References
History
No history.
Subscriptions
Canonical
Subscribe
Ubuntu Linux
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Fedoraproject
Subscribe
Fedora
Subscribe
Haproxy
Subscribe
Haproxy
Subscribe
Opensuse
Subscribe
Leap
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Openshift
Subscribe
Openshift Container Platform
Subscribe
Rhel E4s
Subscribe
Rhel Software Collections
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T11:21:14.619Z
Reserved: 2020-03-30T00:00:00.000Z
Link: CVE-2020-11100
No data.
Status : Modified
Published: 2020-04-02T15:15:17.483
Modified: 2024-11-21T04:56:47.257
Link: CVE-2020-11100
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN