Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

SUSE: 2019:3125-1 Important: HAProxy HTTP Smuggling Advisory

suse
Calendar Grey November 29, 2019
Dist Suse Esm H88
SUSE has released a critical security update for mysql, rectifying a significant vulnerability along with essential enhancements.
An update that solves one vulnerability and has three fixes is now available

Summary

This update for haproxy to version 2.0.10 fixes the following issues: HAProxy was updated to 2.0.10 Security issues fixed: - CVE-2019-18277: Fixed a potential HTTP smuggling in messages with transfer-encoding header missing the "chunked" (bsc#1154980). - Fixed an improper handling of headers which could have led to injecting LFs in H2-to-H1 transfers creating new attack space (bsc#1157712) - Fixed an issue where HEADER frames in idle streams are not rejected and thus trying to decode them HAPrpxy crashes (bsc#1157714). Other issue addressed: - Macro change in the spec file (bsc#1082318) More information regarding the release at: aae20954b3053ce87e Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".

References

#1082318 #1154980 #1157712 #1157714

Cross- CVE-2019-18277

Affected Products:

SUSE Linux Enterprise High Availability 15

https://www.suse.com/security/cve/CVE-2019-18277.html

https://bugzilla.suse.com/1082318

https://bugzilla.suse.com/1154980

https://bugzilla.suse.com/1157712

https://bugzilla.suse.com/1157714

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:3125-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here