CVE-2018-20615

An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a crash. The processing of the PRIORITY flag in a HEADERS frame requires 5 extra bytes, and while these bytes are skipped, the total frame length was not re-checked to make sure they were present in the frame.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 36%
VendorProductVersion
haproxyhaproxy
1.8.0 ≤
𝑥
≤ 1.8.19
haproxyhaproxy
1.9.0
haproxyhaproxy
1.9.0:dev0
haproxyhaproxy
1.9.0:dev1
haproxyhaproxy
1.9.0:dev10
haproxyhaproxy
1.9.0:dev11
haproxyhaproxy
1.9.0:dev2
haproxyhaproxy
1.9.0:dev3
haproxyhaproxy
1.9.0:dev4
haproxyhaproxy
1.9.0:dev5
haproxyhaproxy
1.9.0:dev6
haproxyhaproxy
1.9.0:dev7
haproxyhaproxy
1.9.0:dev8
haproxyhaproxy
1.9.0:dev9
opensuseleap
15.0
canonicalubuntu_linux
16.04
canonicalubuntu_linux
18.04
canonicalubuntu_linux
18.10
redhatopenshift_container_platform
3.11
redhatenterprise_linux
7.0
redhatenterprise_linux
7.4
redhatenterprise_linux
7.5
redhatenterprise_linux
7.6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
haproxy
bullseye (security)
2.2.9-2+deb11u6
fixed
bullseye
2.2.9-2+deb11u6
fixed
stretch
not-affected
jessie
not-affected
bookworm
2.6.12-1+deb12u1
fixed
bookworm (security)
2.6.12-1+deb12u1
fixed
sid
2.9.11-1
fixed
trixie
2.9.11-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
haproxy
cosmic
Fixed 1.8.13-2ubuntu0.1
released
bionic
Fixed 1.8.8-1ubuntu0.3
released
xenial
not-affected
trusty
dne