USN-7431-1: HAProxy vulnerability
Aleandro Prudenzano and Edoardo Geraci discovered that HAProxy incorrectly handled certain uncommon configurations that replace multiple short patterns with a longer one. A remote attacker could use this issue to cause HAProxy to crash, resulting in a denial of service, or possibly execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7431-1?
The severity of USN-7431-1 is considered important due to the potential for denial of service.
How do I fix USN-7431-1?
To fix USN-7431-1, update HAProxy to the latest versions listed in the advisory.
What versions of HAProxy are affected by USN-7431-1?
USN-7431-1 affects HAProxy versions up to 2.9.10-1ubuntu1.2, 2.8.5-1ubuntu3.3, and 2.4.24-0ubuntu0.22.04.2.
What is the impact of USN-7431-1?
The impact of USN-7431-1 includes the potential for HAProxy to crash, leading to a denial of service.
Who discovered the USN-7431-1 vulnerability?
The USN-7431-1 vulnerability was discovered by Aleandro Prudenzano and Edoardo Geraci.