Unrated severityNVD Advisory· Published Apr 2, 2020· Updated Aug 4, 2024
CVE-2020-11100
CVE-2020-11100
Description
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.
Affected products
4- HAProxy/HAProxydescription
- osv-coords3 versionspkg:bitnami/haproxypkg:rpm/suse/haproxy&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015pkg:rpm/suse/haproxy&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP1
>= 1.8.0, < 2.1.4+ 2 more
- (no CPE)range: >= 1.8.0, < 2.1.4
- (no CPE)range: < 2.0.10+git0.ac198b92-3.19.1
- (no CPE)range: < 2.0.10+git0.ac198b92-8.12.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
14- lists.opensuse.org/opensuse-security-announce/2020-04/msg00002.htmlmitrevendor-advisoryx_refsource_SUSE
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/264C7UL3X7L7QE74ZJ557IOUFS3J4QQC/mitrevendor-advisoryx_refsource_FEDORA
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MNW5RZLIX7LOXRLV7WMHX22CI43XSXKW/mitrevendor-advisoryx_refsource_FEDORA
- security.gentoo.org/glsa/202012-22mitrevendor-advisoryx_refsource_GENTOO
- usn.ubuntu.com/4321-1/mitrevendor-advisoryx_refsource_UBUNTU
- www.debian.org/security/2020/dsa-4649mitrevendor-advisoryx_refsource_DEBIAN
- packetstormsecurity.com/files/157323/haproxy-hpack-tbl.c-Out-Of-Bounds-Write.htmlmitrex_refsource_MISC
- www.haproxy.orgmitrex_refsource_MISC
- bugzilla.redhat.com/show_bug.cgimitrex_refsource_CONFIRM
- bugzilla.suse.com/show_bug.cgimitrex_refsource_CONFIRM
- git.haproxy.orgmitrex_refsource_CONFIRM
- lists.debian.org/debian-security-announce/2020/msg00052.htmlmitrex_refsource_CONFIRM
- www.haproxy.org/download/2.1/src/CHANGELOGmitrex_refsource_CONFIRM
- www.mail-archive.com/haproxy%40formilux.org/msg36876.htmlmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.