OSVDB ID: 82769

Title: HAProxy Session Freeing Unspecified DoS

Info

Disclosure

May 14, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

May 14, 2006

Description

HAProxy contains a flaw that may allow a remote denial of service. The issue is due to an uninitialized field in the struct session. This can conceivably be triggered when a session is freed (e.g., an attacker could create numerous sessions to increase the chance of crash), and may result in loss of availability for the service.

Classification

Location: Remote / Network Access
Impact: Loss of Availability
Solution: Upgrade
Exploit: Exploit Public
Disclosure: Vendor Verified
OSVDB: Web Related

Solution

Upgrade to version 1.2.13.1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

HAProxy

HAProxy

1.2.13

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/82769