HAProxy through 2.0.2 allows attackers to cause a denial of service (ha_panic) via vectors related to htx_manage_client_side_cookies in proto_htx.c.
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Haproxy | Haproxy | 1.4 (including) | 1.9.8 (including) |
| Haproxy | Haproxy | 2.0.0 (including) | 2.0.2 (including) |
| Haproxy | Ubuntu | devel | * |
| Haproxy | Ubuntu | trusty | * |