ALASHAPROXY2-2023-001

Related Vulnerabilities: CVE-2022-0711  

A flaw was found in the way HAProxy processed HTTP responses containing the Set-Cookie2 header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability. (CVE-2022-0711)

ALASHAPROXY2-2023-001


Amazon Linux 2 Security Advisory: ALASHAPROXY2-2023-001
Advisory Release Date: 2023-08-04 20:34 Pacific
Advisory Updated Date: 2023-09-25 22:11 Pacific
Severity: Important

Issue Overview:

A flaw was found in the way HAProxy processed HTTP responses containing the Set-Cookie2 header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability. (CVE-2022-0711)


Affected Packages:

haproxy2


Issue Correction:
Run yum update haproxy2 to update your system.

New Packages:
aarch64:
    haproxy2-2.2.17-1.amzn2.0.2.aarch64
    haproxy2-debuginfo-2.2.17-1.amzn2.0.2.aarch64

src:
    haproxy2-2.2.17-1.amzn2.0.2.src

x86_64:
    haproxy2-2.2.17-1.amzn2.0.2.x86_64
    haproxy2-debuginfo-2.2.17-1.amzn2.0.2.x86_64