haproxy-1.8.23-3.el8

エラータID: AXSA:2020-267:02

Release date: 
Tuesday, August 18, 2020 - 08:19
Subject: 
haproxy-1.8.23-3.el8
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

The haproxy packages provide a reliable, high-performance network load balancer for TCP and HTTP-based applications.

The following packages have been upgraded to a later upstream version: haproxy (1.8.23).

Security Fix(es):

* haproxy: HTTP request smuggling issue with transfer-encoding header containing an obfuscated "chunked" value (CVE-2019-18277)

* haproxy: HTTP/2 implementation vulnerable to intermediary encapsulation attacks (CVE-2019-19330)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Asianux Server 8.2 Release Notes linked from the References section.

CVE-2019-18277
A flaw was found in HAProxy before 2.0.6. In legacy mode, messages featuring a transfer-encoding header missing the "chunked" value were not being correctly rejected. The impact was limited but if combined with the "http-reuse always" setting, it could be used to help construct an HTTP request smuggling attack against a vulnerable component employing a lenient parser that would ignore the content-length header as soon as it saw a transfer-encoding one (even if not entirely valid according to the specification).
CVE-2019-19330
The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. haproxy-1.8.23-3.el8.src.rpm
    MD5: 2e3365ea20e18643a8541167fc7eaebc
    SHA-256: 713d4bfce85fe8492b905fdf7f93f34a96192e006ad0e5983481971ae61808bd
    Size: 2.03 MB

Asianux Server 8 for x86_64
  1. haproxy-1.8.23-3.el8.x86_64.rpm
    MD5: 0ca791fa598099702088fcfa036c64ab
    SHA-256: b985ed6b7a35ec019047360e2ccdb804e465729a519e81f02766cc6bdcaac859
    Size: 1.34 MB