haproxy-1.4.22-4.AXS4

エラータID: AXSA:2013-463:01

Release date: 
Thursday, May 30, 2013 - 20:08
Subject: 
haproxy-1.4.22-4.AXS4
Affected Channels: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

HAProxy is a free, fast and reliable solution offering high availability, load balancing, and proxying for TCP and HTTP-based applications. It is particularly suited for web sites crawling under very high loads while needing persistence or Layer7 processing. Supporting tens of thousands of connections is clearly realistic with modern hardware. Its mode of operation makes integration with existing architectures very easy and riskless, while still offering the possibility not to expose fragile web servers to the net.

Security issues fixed with this release:

• CVE-2013-1912
Buffer overflow in HAProxy 1.4 through 1.4.22 and 1.5-dev through 1.5-dev17, when HTTP keep-alive is enabled, using HTTP keywords in TCP inspection rules, and running with rewrite rules that appends to requests, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted pipelined HTTP requests that prevent request realignment from occurring.

Solution: 

Install packages.

Additional Info: 

This is a new package.

Download: 

SRPMS
  1. haproxy-1.4.22-4.AXS4.src.rpm
    MD5: 2d31140dd074604247fcc4247789db1a
    SHA-256: a747974dc93bbe86d8bfd74afc67b738d8935f3305038f5115a0e7e71f1b7d7e
    Size: 815.65 kB

Asianux Server 4 for x86
  1. haproxy-1.4.22-4.AXS4.i686.rpm
    MD5: 95a4442b92dc8a8168ee6cf28575898f
    SHA-256: ae0047dd2b7b0e8cddb0b0aa5bd921b022edd83229ca2336df27f2802333cfee
    Size: 441.05 kB

Asianux Server 4 for x86_64
  1. haproxy-1.4.22-4.AXS4.x86_64.rpm
    MD5: bfd62ae96d7ef124acf5159087b38b2c
    SHA-256: f80877d65bd15aed0248a6a61ece1527d25946893c81df115f7aaaad6b847917
    Size: 450.93 kB