CVE-2019-11323: Medium severity aprox aproxengine vulnerability
HAProxy before 1.9.7 mishandles a reload with rotated keys, which triggers use of uninitialized, and very predictable, HMAC keys. This is related to an include/types/sslsock.h error.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-11323?
CVE-2019-11323 is a vulnerability in HAProxy versions before 1.9.7 that mishandles a reload with rotated keys, leading to the use of uninitialized and predictable HMAC keys.
What is the severity of CVE-2019-11323?
The severity of CVE-2019-11323 is medium, with a severity value of 5.9.
How does CVE-2019-11323 affect HAProxy?
CVE-2019-11323 affects HAProxy versions before 1.9.7, specifically when performing a reload with rotated keys.
How can I fix CVE-2019-11323 in HAProxy?
To fix CVE-2019-11323 in HAProxy, you should update to version 1.9.7 or later.
Are there any references to learn more about CVE-2019-11323?
Yes, you can refer to the following links for more information: [1] http://git.haproxy.org/?p=haproxy.git;a=commit;h=8ef706502aa2000531d36e4ac56dbdc7c30f718d [2] https://www.mail-archive.com/haproxy@formilux.org/msg33410.html