Sicherheit: Denial of Service in haproxy
Aktuelle Meldungen Distributionen
Name: Denial of Service in haproxy
ID: FEDORA-2018-0b038c7047
Distribution: Fedora
Plattformen: Fedora 29
Datum: Di, 2. Oktober 2018, 22:56
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14645
Applikationen: HAproxy


Fedora Update Notification
2018-10-02 19:26:59.107984

Name : haproxy
Product : Fedora 29
Version : 1.8.14
Release : 1.fc29
URL : http://www.haproxy.org/
Summary : HAProxy reverse proxy for high availability environments
Description :
HAProxy is a TCP/HTTP reverse proxy which is particularly suited for high
availability environments. Indeed, it can:
- route HTTP requests depending on statically assigned cookies
- spread load among several servers while assuring server persistence
through the use of HTTP cookies
- switch to backup servers in the event a main one fails
- accept connections to special ports dedicated to service monitoring
- stop accepting connections without breaking existing ones
- add, modify, and delete HTTP headers in both directions
- block requests matching particular patterns
- report detailed status to authenticated users from a URI
intercepted from the application

Update Information:

Update to 1.8.14, which includes fix for CVE-2018-14645.

[ 1 ] Bug #1631538 - CVE-2018-14645 haproxy: Out-of-bounds read in HPACK
decoder [fedora-all]
[ 2 ] Bug #1610066 - haproxy-1.8.14 is available

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2018-0b038c7047' at the command
line. For more information, refer to the dnf documentation available at

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org
Pro-Linux @Twitter
Neue Nachrichten