Oval Definition:oval:org.opensuse.security:def:201820102
Revision Date:2022-09-02Version:1
Title:CVE-2018-20102
Description:

An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14. Due to a missing check when validating DNS responses, remote attackers might be able read the 16 bytes corresponding to an AAAA record from the non-initialized part of the buffer, possibly accessing anything that was left on the stack, or even past the end of the 8193-byte buffer, depending on the value of accepted_payload_size.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2018-20102
SUSE-SU-2019:0061-1
openSUSE-SU-2019:0044-1
Mitre CVE-2018-20102
SUSE CVE-2018-20102
SUSE-SU-2019:0061-1
openSUSE-SU-2019:0044-1
Platform(s):openSUSE Leap 15.0
SUSE Linux Enterprise High Availability 15
SUSE Linux Enterprise High Availability 15 SP1
SUSE Linux Enterprise High Performance Computing 15 SP1
SUSE Linux Enterprise Server 15 SP1
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server for SAP Applications 12 SP2
SUSE Linux Enterprise Server for SAP Applications 12 SP4
SUSE Linux Enterprise Server for SAP Applications 15 SP1
SUSE Linux Enterprise Storage 6
SUSE Manager Proxy 4.0
SUSE Manager Retail Branch Server 4.0
SUSE Manager Server 4.0
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • haproxy-1.8.15~git0.6b6a350a-lp150.2.6 is installed
  • AND haproxy is signed with openSUSE key
  • Definition Synopsis
  • SUSE Linux Enterprise High Availability 15 is installed
  • AND haproxy-1.8.15~git0.6b6a350a-3.6 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Availability 15 is installed
  • AND haproxy-1.8.15~git0.6b6a350a-3.6 is installed
  • OR Package Information
  • SUSE Linux Enterprise High Availability 15 SP1 is installed
  • AND haproxy-1.8.17~git0.e89d25b2-6 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND haproxy is not affected
  • Definition Synopsis
  • SUSE Linux Enterprise High Availability 15 SP1 is installed
  • AND haproxy-1.8.17~git0.e89d25b2-6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise High Availability 15 SP1 is installed
  • AND haproxy-1.8.17~git0.e89d25b2-6.23 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server for SAP Applications 12 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP2 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP4 is installed
  • AND haproxy is not affected
  • Definition Synopsis
  • Release Information
  • SUSE OpenStack Cloud 8 is installed
  • OR SUSE OpenStack Cloud Crowbar 8 is installed
  • AND haproxy is not affected
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Availability 15 SP1 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP1 is installed
  • OR SUSE Linux Enterprise Server 15 SP1 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP1 is installed
  • OR SUSE Manager Proxy 4.0 is installed
  • OR SUSE Manager Retail Branch Server 4.0 is installed
  • OR SUSE Manager Server 4.0 is installed
  • AND haproxy-1.8.17~git0.e89d25b2-6.23 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server for SAP Applications 12 SP4 is installed
  • AND haproxy is not affected
  • BACK