CVE-2015-3281

The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of previous requests) via a crafted request.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 25%
VendorProductVersion
debiandebian_linux
8.0
haproxyhaproxy
1.5:dev
haproxyhaproxy
1.5:dev0
haproxyhaproxy
1.5:dev1
haproxyhaproxy
1.5:dev10
haproxyhaproxy
1.5:dev11
haproxyhaproxy
1.5:dev12
haproxyhaproxy
1.5:dev13
haproxyhaproxy
1.5:dev14
haproxyhaproxy
1.5:dev15
haproxyhaproxy
1.5:dev16
haproxyhaproxy
1.5:dev17
haproxyhaproxy
1.5:dev18
haproxyhaproxy
1.5:dev19
haproxyhaproxy
1.5:dev2
haproxyhaproxy
1.5:dev3
haproxyhaproxy
1.5:dev4
haproxyhaproxy
1.5:dev5
haproxyhaproxy
1.5:dev6
haproxyhaproxy
1.5:dev7
haproxyhaproxy
1.5:dev8
haproxyhaproxy
1.5:dev9
haproxyhaproxy
1.5.0
haproxyhaproxy
1.5.1
haproxyhaproxy
1.5.2
haproxyhaproxy
1.5.3
haproxyhaproxy
1.5.4
haproxyhaproxy
1.5.5
haproxyhaproxy
1.5.6
haproxyhaproxy
1.5.7
haproxyhaproxy
1.5.8
haproxyhaproxy
1.5.9
haproxyhaproxy
1.5.10
haproxyhaproxy
1.5.11
haproxyhaproxy
1.5.12
haproxyhaproxy
1.5.13
haproxyhaproxy
1.6:dev0
canonicalubuntu_linux
14.10
canonicalubuntu_linux
15.04
opensuseopensuse
13.2
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_server_aus
7.3
redhatenterprise_linux_server_aus
7.4
redhatenterprise_linux_server_aus
7.6
redhatenterprise_linux_server_eus
7.1
redhatenterprise_linux_server_eus
7.2
redhatenterprise_linux_server_eus
7.3
redhatenterprise_linux_server_eus
7.4
redhatenterprise_linux_server_eus
7.5
redhatenterprise_linux_server_eus
7.6
redhatenterprise_linux_server_tus
7.3
redhatenterprise_linux_server_tus
7.6
redhatenterprise_linux_workstation
7.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
haproxy
bullseye (security)
2.2.9-2+deb11u6
fixed
bullseye
2.2.9-2+deb11u6
fixed
squeeze
not-affected
bookworm
2.6.12-1+deb12u1
fixed
bookworm (security)
2.6.12-1+deb12u1
fixed
sid
2.9.11-1
fixed
trixie
2.9.11-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
haproxy
vivid
Fixed 1.5.10-1ubuntu0.1
released
utopic
Fixed 1.5.4-1ubuntu2.1
released
trusty
dne
precise
not-affected