Oval Definition:oval:org.opensuse.security:def:202011100
Revision Date:2022-09-02Version:1
Title:CVE-2020-11100
Description:

In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2020-11100
SUSE-SU-2020:0851-1
SUSE-SU-2020:0852-1
openSUSE-SU-2020:0444-1
Mitre CVE-2020-11100
SUSE CVE-2020-11100
SUSE-SU-2020:0851-1
SUSE-SU-2020:0852-1
openSUSE-SU-2020:0444-1
Platform(s):openSUSE Leap 15.1
openSUSE Tumbleweed
SUSE Linux Enterprise High Availability 15
SUSE Linux Enterprise High Availability 15 SP1
SUSE Linux Enterprise High Performance Computing 15 SP1
SUSE Linux Enterprise Server 15 SP1
SUSE Linux Enterprise Server for SAP Applications 12 SP1
SUSE Linux Enterprise Server for SAP Applications 12 SP2
SUSE Linux Enterprise Server for SAP Applications 12 SP4
SUSE Linux Enterprise Server for SAP Applications 12 SP5
SUSE Linux Enterprise Server for SAP Applications 15 SP1
SUSE Linux Enterprise Storage 6
SUSE Manager Proxy 4.0
SUSE Manager Retail Branch Server 4.0
SUSE Manager Server 4.0
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud 9
SUSE OpenStack Cloud Crowbar 8
SUSE OpenStack Cloud Crowbar 9
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • haproxy-2.0.10+git0.ac198b92-lp151.2.9 is installed
  • AND haproxy is signed with openSUSE key
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Availability 15 is installed
  • AND haproxy-2.0.10+git0.ac198b92-3.19 is installed
  • OR Package Information
  • SUSE Linux Enterprise High Availability 15 SP1 is installed
  • AND haproxy-2.0.10+git0.ac198b92-8.12 is installed
  • Definition Synopsis
  • Release Information
  • SUSE OpenStack Cloud 9 is installed
  • OR SUSE OpenStack Cloud Crowbar 9 is installed
  • AND haproxy is not affected
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND haproxy is not affected
  • Definition Synopsis
  • SUSE Linux Enterprise High Availability 15 SP1 is installed
  • AND haproxy-2.0.10+git0.ac198b92-8.12 is installed
  • Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND haproxy-2.4.4+git0.acb1d0bea-1.2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise High Availability 15 SP1 is installed
  • AND haproxy-2.0.10+git0.ac198b92-8.12.1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Availability 15 SP1 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP1 is installed
  • OR SUSE Linux Enterprise Server 15 SP1 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP1 is installed
  • OR SUSE Manager Proxy 4.0 is installed
  • OR SUSE Manager Retail Branch Server 4.0 is installed
  • OR SUSE Manager Server 4.0 is installed
  • AND haproxy-2.0.10+git0.ac198b92-8.12.1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Server for SAP Applications 12 SP1 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP2 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP4 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 12 SP5 is installed
  • AND haproxy is not affected
  • Definition Synopsis
  • Release Information
  • SUSE OpenStack Cloud 8 is installed
  • OR SUSE OpenStack Cloud Crowbar 8 is installed
  • AND haproxy is not affected
  • Definition Synopsis
  • SUSE Linux Enterprise Server for SAP Applications 12 SP5 is installed
  • AND haproxy is not affected
  • Definition Synopsis
  • SUSE Linux Enterprise Server for SAP Applications 12 SP4 is installed
  • AND haproxy is not affected
  • BACK