Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia 9 Advisory: 2023-0320 Moderate: Haproxy Access Control Exploit

mageia
Calendar Grey November 20, 2023
Dist Mageia Esm H88
Update HAProxy to the latest version 2.8.3 to fix vulnerabilities and improve access management techniques.
Haproxy has fixed security and other issues in last upstream version 2.8.3 of branch 2.8 Default user access are now commented out to prevent local action possible exploit and pre...

Summary

Haproxy has fixed security and other issues in last upstream version 2.8.3 of branch 2.8
Default user access are now commented out to prevent local action possible exploit and prevent further rpmnew on future updates.
Use a check script to have config check result in error log on failure.
Fix corruption with non empty access log.
Fixed major bug list: - quic: Really ignore malformed ACK frames - http-ana: Get a fresh trash buffer for each header value replacement - h3: reject header values containing invalid chars - http: reject any empty content-length header value (CVE-2023-40225)
Fixed medium bug list: - quic: fix tasklet_wakeup loop on connection closing - stconn: Update stream expiration date on blocked sends - stconn: Wake applets on sending path if there is a pending shutdown - stconn: Don't block sends if there is a pending shutdown - h1-htx: Ensure chunked parsing with full output buffer - applet: Fix API for function to push new data in channels buffer - stconn: Report rea...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=32319

- https://www.haproxy.org/download/2.8/src/CHANGELOG

- https://www.cve.org/CVERecord?id=CVE-2023-40225

Resolution

SRPMS

- 9/core/haproxy-2.8.3-9.mga9

Publication date: 20 Nov 2023
URL: https://advisories.mageia.org/MGASA-2023-0320.html
Type: security
CVE: CVE-2023-40225

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here