CVE-2018-20102: High severity HAProxy HAProxy vulnerability
An out-of-bounds read in dnsvalidatednsresponse in dns.c was discovered in HAProxy through 1.8.14. Due to a missing check when validating DNS responses, remote attackers might be able read the 16 bytes corresponding to an AAAA record from the non-initialized part of the buffer, possibly accessing anything that was left on the stack, or even past the end of the 8193-byte buffer, depending on the value of acceptedpayloadsize.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-20102?
CVE-2018-20102 is an out-of-bounds read vulnerability discovered in HAProxy through version 1.8.14.
How severe is CVE-2018-20102?
CVE-2018-20102 has a severity score of 7.5, which is considered high.
Which software is affected by CVE-2018-20102?
The affected software includes HAProxy versions 1.8.14 to 1.8.19, 2.2.9, 2.6.12, and 2.6.15.
How can I fix CVE-2018-20102?
To fix CVE-2018-20102, update HAProxy to version 1.8.19-1+deb10u3, 1.8.19-1+deb10u4, 2.2.9-2+deb11u5, 2.6.12-1, or 2.6.15-1.
Where can I find more information about CVE-2018-20102?
You can find more information about CVE-2018-20102 in the references provided: http://git.haproxy.org/?p=haproxy.git;a=commit;h=efbbdf72992cd20458259962346044cafd9331c0, http://www.securityfocus.com/bid/106223, https://access.redhat.com/errata/RHBA-2019:0326