Oval Definition:oval:org.opensuse.security:def:201820615
Revision Date:2022-09-02Version:1
Title:CVE-2018-20615
Description:

An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a crash. The processing of the PRIORITY flag in a HEADERS frame requires 5 extra bytes, and while these bytes are skipped, the total frame length was not re-checked to make sure they were present in the frame.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2018-20615
SUSE-SU-2019:0232-1
openSUSE-SU-2019:0166-1
Mitre CVE-2018-20615
SUSE CVE-2018-20615
SUSE-SU-2019:0232-1
openSUSE-SU-2019:0166-1
Platform(s):openSUSE Leap 15.0
openSUSE Tumbleweed
SUSE Linux Enterprise High Availability 15
SUSE Linux Enterprise High Availability 15 SP1
SUSE Linux Enterprise High Performance Computing 15 SP1
SUSE Linux Enterprise Server 15 SP1
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server for SAP Applications 12 SP2
SUSE Linux Enterprise Server for SAP Applications 12 SP4
SUSE Linux Enterprise Server for SAP Applications 15 SP1
SUSE Linux Enterprise Storage 6
SUSE Manager Proxy 4.0
SUSE Manager Retail Branch Server 4.0
SUSE Manager Server 4.0
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • haproxy-1.8.17~git0.e89d25b2-lp150.2.9 is installed
  • AND haproxy is signed with openSUSE key
  • Definition Synopsis
  • SUSE Linux Enterprise High Availability 15 is installed
  • AND haproxy-1.8.17~git0.e89d25b2-3.9 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Availability 15 is installed
  • AND haproxy-1.8.17~git0.e89d25b2-3.9 is installed
  • OR Package Information
  • SUSE Linux Enterprise High Availability 15 SP1 is installed
  • AND haproxy-1.8.17~git0.e89d25b2-6 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND haproxy is not affected
  • Definition Synopsis
  • SUSE Linux Enterprise High Availability 15 SP1 is installed
  • AND haproxy-1.8.17~git0.e89d25b2-6 is installed
  • Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND haproxy-2.4.4+git0.acb1d0bea-1.2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise High Availability 15 SP1 is installed
  • AND haproxy-1.8.17~git0.e89d25b2-6.23 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server for SAP Applications 12 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP2 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP4 is installed
  • AND haproxy is not affected
  • Definition Synopsis
  • Release Information
  • SUSE OpenStack Cloud 8 is installed
  • OR SUSE OpenStack Cloud Crowbar 8 is installed
  • AND haproxy is not affected
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Availability 15 SP1 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP1 is installed
  • OR SUSE Linux Enterprise Server 15 SP1 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP1 is installed
  • OR SUSE Manager Proxy 4.0 is installed
  • OR SUSE Manager Retail Branch Server 4.0 is installed
  • OR SUSE Manager Server 4.0 is installed
  • AND haproxy-1.8.17~git0.e89d25b2-6.23 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server for SAP Applications 12 SP4 is installed
  • AND haproxy is not affected
  • BACK