haproxy-2.4.22-1.el9
エラータID: AXSA:2023-6671:04
The haproxy packages provide a reliable, high-performance network load balancer for TCP and HTTP-based applications.
Security Fix(es):
* haproxy: data leak via fcgi requests (CVE-2023-0836)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2023-0836
An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when encoding the FCGI_BEGIN_REQUEST record. Sensitive data may be disclosed to configured FastCGI backends in an unexpected way.
Update packages.
An information leak vulnerability was discovered in HAProxy 2.1, 2.2 before 2.2.27, 2.3, 2.4 before 2.4.21, 2.5 before 2.5.11, 2.6 before 2.6.8, 2.7 before 2.7.1. There are 5 bytes left uninitialized in the connection buffer when encoding the FCGI_BEGIN_REQUEST record. Sensitive data may be disclosed to configured FastCGI backends in an unexpected way.
N/A
SRPMS
- haproxy-2.4.22-1.el9.src.rpm
MD5: 036797844da8164ada32a495f4350fcc
SHA-256: 2f7e17e56ae5573273813c304c693787d8778bb06174064a06252a5a8424aafc
Size: 3.50 MB
Asianux Server 9 for x86_64
- haproxy-2.4.22-1.el9.x86_64.rpm
MD5: d089ce16fe9ab3692b72646170ecdfcd
SHA-256: 66cd73b2b0c8a55b5065010780e12e76c9f44911508df59e442c72768d805a82
Size: 2.16 MB