Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

SUSE: 2019:3126-1 Important: haproxy HTTP Smuggling and Crash Fix

suse
Calendar Grey November 29, 2019
Dist Suse Esm H88
Debian Security Patch for Nginx tackles several vulnerabilities with precision. Upgrade immediately to maintain system protection.
An update that solves one vulnerability and has three fixes is now available

Summary

This update for haproxy to version 2.0.10 fixes the following issues: HAProxy was updated to 2.0.10 Security issues fixed: - CVE-2019-18277: Fixed a potential HTTP smuggling in messages with transfer-encoding header missing the "chunked" (bsc#1154980). - Fixed an improper handling of headers which could have led to injecting LFs in H2-to-H1 transfers creating new attack space (bsc#1157712) - Fixed an issue where HEADER frames in idle streams are not rejected and thus trying to decode them HAPrpxy crashes (bsc#1157714). Other issue addressed: - Macro change in the spec file (bsc#1082318) More information regarding the release at: http://git.haproxy.org/?p=haproxy-2.0.git;a=commit;h=ac198b92d461515551b95d aae20954b3053ce87e Patch Instructions:

References

#1082318 #1154980 #1157712 #1157714

Cross- CVE-2019-18277

Affected Products:

SUSE Linux Enterprise High Availability 15-SP1

https://www.suse.com/security/cve/CVE-2019-18277.html

https://bugzilla.suse.com/1082318

https://bugzilla.suse.com/1154980

https://bugzilla.suse.com/1157712

https://bugzilla.suse.com/1157714

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:3126-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here