A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.
The product reads data past the end, or before the beginning, of the intended buffer.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Haproxy | Haproxy | * | 1.8.14 (including) |
Haproxy | Ubuntu | bionic | * |
Haproxy | Ubuntu | upstream | * |
Red Hat OpenShift Container Platform 3.10 | RedHat | haproxy-0:1.8.14-2.el7 | * |
Red Hat OpenShift Container Platform 3.9 | RedHat | atomic-openshift-0:3.9.60-1.git.0.f8b38ff.el7 | * |
Red Hat OpenShift Container Platform 3.9 | RedHat | atomic-openshift-dockerregistry-0:3.9.60-1.git.353.1da3b27.el7 | * |
Red Hat OpenShift Container Platform 3.9 | RedHat | atomic-openshift-web-console-0:3.9.60-1.git.277.be8dbdd.el7 | * |
Red Hat OpenShift Container Platform 3.9 | RedHat | golang-github-prometheus-node_exporter-0:3.9.60-1.git.1063.df94c95.el7 | * |
Red Hat OpenShift Container Platform 3.9 | RedHat | haproxy-0:1.8.14-2.el7 | * |
Red Hat OpenShift Container Platform 3.9 | RedHat | openshift-ansible-0:3.9.60-1.git.0.f0ebfaa.el7 | * |
Red Hat OpenShift Container Platform 3.9 | RedHat | rubygem-ffi-0:1.9.25-4.el7_5 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-haproxy18-haproxy-0:1.8.4-3.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | RedHat | rh-haproxy18-haproxy-0:1.8.4-3.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | RedHat | rh-haproxy18-haproxy-0:1.8.4-3.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | RedHat | rh-haproxy18-haproxy-0:1.8.4-3.el7 | * |