=========================================================================Ubuntu Security Notice USN-5063-1
September 08, 2021

haproxy vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 21.04
- Ubuntu 20.04 LTS

Summary:

HAProxy could be made to expose sensitive information over the network.

Software Description:
- haproxy: fast and reliable load balancing reverse proxy

Details:

Ori Hollander discovered that HAProxy incorrectly handled HTTP header name
length encoding. A remote attacker could possibly use this issue to inject
a duplicate content-length header and perform request smuggling attacks.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 21.04:
  haproxy                         2.2.9-1ubuntu0.2

Ubuntu 20.04 LTS:
  haproxy                         2.0.13-2ubuntu0.3

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-5063-1
  CVE-2021-40346

Package Information:
  https://launchpad.net/ubuntu/+source/haproxy/2.2.9-1ubuntu0.2
  https://launchpad.net/ubuntu/+source/haproxy/2.0.13-2ubuntu0.3

Ubuntu 5063-1: HAProxy vulnerabilities

September 8, 2021
HAProxy could be made to expose sensitive information over the network.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 21.04: haproxy 2.2.9-1ubuntu0.2 Ubuntu 20.04 LTS: haproxy 2.0.13-2ubuntu0.3 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5063-1

CVE-2021-40346

Severity
September 08, 2021

Package Information

https://launchpad.net/ubuntu/+source/haproxy/2.2.9-1ubuntu0.2 https://launchpad.net/ubuntu/+source/haproxy/2.0.13-2ubuntu0.3

Related News