5
CVSSv2

CVE-2018-20615

Published: 21/03/2019 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

An out-of-bounds read issue exists in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x up to and including 1.9.0 which can result in a crash. The processing of the PRIORITY flag in a HEADERS frame requires 5 extra bytes, and while these bytes are skipped, the total frame length was not re-checked to make sure they were present in the frame.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

haproxy haproxy

haproxy haproxy 1.9.0

opensuse leap 15.0

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 18.10

redhat enterprise linux 7.4

redhat enterprise linux 7.0

redhat enterprise linux 7.5

redhat openshift container platform 3.11

redhat enterprise linux 7.6

Vendor Advisories

Several security issues were fixed in HAProxy ...
Synopsis Important: rh-haproxy18-haproxy security update Type/Severity Security Advisory: Important Topic An update for rh-haproxy18-haproxy is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scori ...
Synopsis Moderate: OpenShift Container Platform 310 haproxy security update Type/Severity Security Advisory: Moderate Topic An update for haproxy is now available for Red Hat OpenShift Container Platform 310Red Hat Product Security has rated this update as having a security impact of Moderate A Common V ...
Synopsis Moderate: OpenShift Container Platform 39 haproxy security update Type/Severity Security Advisory: Moderate Topic An update for haproxy is now available for Red Hat OpenShift Container Platform 39Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vul ...