CVE-2018-20615: High severity HAProxy HAProxy vulnerability
An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a crash. The processing of the PRIORITY flag in a HEADERS frame requires 5 extra bytes, and while these bytes are skipped, the total frame length was not re-checked to make sure they were present in the frame.
Other sources
HAProxy before versions 1.8.17 and 1.9.1 mishandles when a priority flag is set on too short a HEADERS frame in the HTTP/2 decoder, allowing for an out-of-bounds read and subsequent crash. A remote attacker could exploit this to cause a denial of service.
Those who do not use HTTP/2 are unaffected.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-20615.
What is the severity level of CVE-2018-20615?
The severity level of CVE-2018-20615 is high.
Which software versions are affected by CVE-2018-20615?
The affected software versions for CVE-2018-20615 include HAProxy 1.8.x and 1.9.x through 1.9.0.
How does CVE-2018-20615 impact the system?
CVE-2018-20615 can result in a crash due to an out-of-bounds read issue in the HTTP/2 protocol decoder.
Are there any remedies available for CVE-2018-20615?
Yes, there are remedies available for CVE-2018-20615. Please refer to the references provided for more information.