First published: Tue May 28 2019(Updated: )
USN-3995-1 fixed a vulnerability in keepalived. This update provides the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. Original advisory details: It was discovered that Keepalived incorrectly handled certain HTTP status response codes. A remote attacker could use this issue to cause Keepalived to crash, resulting in a denial of service, or possibly execute arbitrary code.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/keepalived | <1:1.2.7-1ubuntu1+esm1 | 1:1.2.7-1ubuntu1+esm1 |
=14.04 | ||
All of | ||
ubuntu/keepalived | <1:1.2.2-3ubuntu1.2 | 1:1.2.2-3ubuntu1.2 |
=12.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is USN-3995-2.
The title of the vulnerability is USN-3995-2: Keepalived vulnerability.
The software affected by this vulnerability is Keepalived version 1:1.2.7-1ubuntu1+esm1 on Ubuntu 12.04 and version 1:1.2.2-3ubuntu1.2 on Ubuntu 14.04.
The severity of this vulnerability is not mentioned in the provided information.
To fix this vulnerability, you should update Keepalived to the recommended version provided in the Ubuntu Security Notice (USN-3995-2).