Oval Definition:oval:com.redhat.rhsa:def:20131120
Revision Date:2013-07-30Version:638
Title:RHSA-2013:1120: haproxy security update (Moderate)
Description:HAProxy provides high availability, load balancing, and proxying for TCP and HTTP-based applications.

  • A flaw was found in the way HAProxy handled requests when the proxy's configuration ("/etc/haproxy/haproxy.cfg") had certain rules that use the hdr_ip criterion. A remote attacker could use this flaw to crash HAProxy instances that use the affected configuration. (CVE-2013-2175)

    Red Hat would like to thank HAProxy upstream for reporting this issue. Upstream acknowledges David Torgerson as the original reporter.

    HAProxy is released as a Technology Preview in Red Hat Enterprise Linux 6. More information about Red Hat Technology Previews is available at https://access.redhat.com/support/offerings/techpreview/

    All users of haproxy are advised to upgrade to this updated package, which contains a backported patch to correct this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2013-2175
    RHSA-2013:1120
    RHSA-2013:1120-00
    RHSA-2013:1120-01
    RHSA-2013:1120-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND haproxy is earlier than 0:1.4.22-5.el6_4
  • AND haproxy is signed with Red Hat redhatrelease2 key
  • BACK