Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

SUSE: 2019:3288-1 Important: haproxy HTTP Smuggling Fix

suse
Calendar Grey December 12, 2019
Dist Suse Esm H88
SUSE Security Bulletin tackles critical vulnerabilities in nginx, offering remediation steps for impacted versions.
An update that fixes one vulnerability is now available

Summary

This update for haproxy fixes the following issues: - CVE-2019-18277: Fixed HTTP smuggling in messages with transfer-encoding header missing the "chunked" value (bsc#1154980). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2019-3288=1 - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2019-3288=1 - SUSE OpenStack Cloud 9: zypper in -t patch SUSE-OpenStack-Cloud-9-2019-3288=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2019-3288=1 - SUSE OpenStack Cloud 7:

References

#1154980

Cross- CVE-2019-18277

Affected Products:

SUSE OpenStack Cloud Crowbar 9

SUSE OpenStack Cloud Crowbar 8

SUSE OpenStack Cloud 9

SUSE OpenStack Cloud 8

SUSE OpenStack Cloud 7

SUSE Linux Enterprise High Availability 12-SP5

SUSE Linux Enterprise High Availability 12-SP4

SUSE Linux Enterprise High Availability 12-SP3

HPE Helion Openstack 8

https://www.suse.com/security/cve/CVE-2019-18277.html

https://bugzilla.suse.com/1154980

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:3288-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here