CVE-2015-3281: Buffer Overflow
The bufferslowrealign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of previous requests) via a crafted request.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3281?
CVE-2015-3281 has been classified as having a medium severity due to potential unauthorized access to sensitive information.
How do I fix CVE-2015-3281?
To fix CVE-2015-3281, upgrade HAProxy to version 1.5.14 or later.
What types of attacks can exploit CVE-2015-3281?
CVE-2015-3281 can be exploited by remote attackers sending crafted requests that leverage uninitialized memory access.
Which versions of HAProxy are affected by CVE-2015-3281?
HAProxy versions 1.5.x before 1.5.14 and 1.6-dev prior to the patch are affected by CVE-2015-3281.
What kind of data is at risk due to CVE-2015-3281?
CVE-2015-3281 can expose uninitialized memory contents from previous requests, posing a risk of sensitive information disclosure.