Oval Definition:oval:org.mitre.oval:def:20471
Revision Date:2014-02-17Version:11
Title:RHSA-2013:0868: haproxy security update (Moderate)
Description:Buffer overflow in HAProxy 1.4 through 1.4.22 and 1.5-dev through 1.5-dev17, when HTTP keep-alive is enabled, using HTTP keywords in TCP inspection rules, and running with rewrite rules that appends to requests, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted pipelined HTTP requests that prevent request realignment from occurring.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2013:0868
CVE-2013-1912
RHSA-2013:0868-01
Platform(s):CentOS Linux 6
Red Hat Enterprise Linux 6
Product(s):haproxy
Definition Synopsis
  • haproxy is earlier than 0:1.4.22-4.el6_4
  • AND Redhat 6 or Centos 6 release
  • The operating system installed on the system is Red Hat Enterprise Linux 6
  • OR The operating system installed on the system is CentOS Linux 6.x
  • BACK