• [SECURITY] [DSA 4649-1] haproxy security update

    From Sebastien Delafond@1:229/2 to All on Thu Apr 2 15:20:02 2020
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4649-1 [email protected] https://www.debian.org/security/ Sebastien Delafond
    April 02, 2020 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : haproxy
    CVE ID : CVE-2020-11100

    Felix Wilhelm of Google Project Zero discovered that HAProxy, a TCP/HTTP reverse proxy, did not properly handle HTTP/2 headers. This would allow
    an attacker to write arbitrary bytes around a certain location on the
    heap, resulting in denial-of-service or potential arbitrary code
    execution.

    For the stable distribution (buster), this problem has been fixed in
    version 1.8.19-1+deb10u2.

    We recommend that you upgrade your haproxy packages.

    For the detailed security status of haproxy please refer to
    its security tracker page at: https://security-tracker.debian.org/tracker/haproxy

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQEzBAEBCgAdFiEEAqSkbVtrXP4xJMh3EL6Jg/PVnWQFAl6F5I0ACgkQEL6Jg/PV nWQPtAgAlebr3o7KaSYcMAfJCsEzCJKPT5tqk+tpcELkDjm3XJgXh8o8+pUfz4x8 I/cz/+sDy6CsSLUrR0699PH9c1EYwhfkyeqxaPg0+BrjSarIAkkJVGIjdSS9in51 ws+JwEUEncLku26MnZO81Ju6HM/tsw+2FitOMYwyU34qrwyaggtD6JBlZjfqk/7M 71YQmYASrWxUwYh3GSLlHC8u3BDyTD/aU8xbgn85LIwX6uXYl/V4iI9DzR3pk5cr 7Flylu15T/W4+7iQ0QSmGgMVPJp4G6Koi2Lj0LiorGIc4L8iq8EpGvjU3t9sBig6 q9nPtEOTeL7QSky9m1sKFjcLgSfGoA==
    =31YW
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)