Sicherheit: Ausführen beliebiger Kommandos in haproxy
Aktuelle Meldungen Distributionen
Name: Ausführen beliebiger Kommandos in haproxy
ID: FEDORA-2020-16cd111544
Distribution: Fedora
Plattformen: Fedora 30
Datum: So, 12. April 2020, 00:26
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11100
Applikationen: HAproxy


Fedora Update Notification
2020-04-11 21:50:51.070260

Name : haproxy
Product : Fedora 30
Version : 1.8.25
Release : 1.fc30
URL : http://www.haproxy.org/
Summary : HAProxy reverse proxy for high availability environments
Description :
HAProxy is a TCP/HTTP reverse proxy which is particularly suited for high
availability environments. Indeed, it can:
- route HTTP requests depending on statically assigned cookies
- spread load among several servers while assuring server persistence
through the use of HTTP cookies
- switch to backup servers in the event a main one fails
- accept connections to special ports dedicated to service monitoring
- stop accepting connections without breaking existing ones
- add, modify, and delete HTTP headers in both directions
- block requests matching particular patterns
- report detailed status to authenticated users from a URI
intercepted from the application

Update Information:

Security fix for CVE-2020-11100)

* Thu Apr 2 2020 Ryan O'Hara <rohara@redhat.com> - 1.8.25-1
- Update to 1.8.25 (CVE-2020-11100)

[ 1 ] Bug #1819111 - CVE-2020-11100 haproxy: malformed HTTP/2 requests can
lead to out-of-bounds writes

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2020-16cd111544' at the command
line. For more information, refer to the dnf documentation available at

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org
Pro-Linux @Facebook
Neue Nachrichten