CVE Vulnerabilities

CVE-2025-32464

Comparison Using Wrong Factors

Published: Apr 09, 2025 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.8 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
Ubuntu
MEDIUM

HAProxy 2.2 through 3.1.6, in certain uncommon configurations, has a sample_conv_regsub heap-based buffer overflow because of mishandling of the replacement of multiple short patterns with a longer one.

Weakness

The code performs a comparison between two entities, but the comparison examines the wrong factors or characteristics of the entities, which can lead to incorrect results and resultant weaknesses.

Affected Software

Name Vendor Start Version End Version
Haproxy Ubuntu devel *
Haproxy Ubuntu jammy *
Haproxy Ubuntu noble *
Haproxy Ubuntu oracular *

Potential Mitigations

References