CVE-2013-1912
published 2013-04-10CVE-2013-1912: Buffer overflow in HAProxy 1.4 through 1.4.22 and 1.5-dev through 1.5-dev17, when HTTP keep-alive is enabled, using HTTP keywords in TCP inspection rules, and…
PriorityP336medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
5.46%
91.9th percentile
Buffer overflow in HAProxy 1.4 through 1.4.22 and 1.5-dev through 1.5-dev17, when HTTP keep-alive is enabled, using HTTP keywords in TCP inspection rules, and running with rewrite rules that appends to requests, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted pipelined HTTP requests that prevent request realignment from occurring.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | haproxy | < haproxy 1.4.23-1 (bookworm) | haproxy 1.4.23-1 (bookworm) |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | >= 0 < 1.4.23-1 | 1.4.23-1 |
| haproxy | haproxy | >= 0 < 1.4.23-1 | 1.4.23-1 |
| haproxy | haproxy | >= 0 < 1.4.23-1 | 1.4.23-1 |
| haproxy | haproxy | >= 0 < 1.4.23-1 | 1.4.23-1 |
CVSS provenance
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv5.1MEDIUM
vendor_debian5.1MEDIUM
vendor_redhat5.1MEDIUM
vendor_ubuntu5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xgv2-5whc-jjqv: Buffer overflow in HAProxy 1
ghsa_unreviewed·2022-05-17
CVE-2013-1912 [MEDIUM] CWE-119 GHSA-xgv2-5whc-jjqv: Buffer overflow in HAProxy 1
Buffer overflow in HAProxy 1.4 through 1.4.22 and 1.5-dev through 1.5-dev17, when HTTP keep-alive is enabled, using HTTP keywords in TCP inspection rules, and running with rewrite rules that appends to requests, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted pipelined HTTP requests that prevent request realignment from occurring.
OSV
CVE-2013-1912: Buffer overflow in HAProxy 1
osv·2013-04-10·CVSS 5.1
CVE-2013-1912 [MEDIUM] CVE-2013-1912: Buffer overflow in HAProxy 1
Buffer overflow in HAProxy 1.4 through 1.4.22 and 1.5-dev through 1.5-dev17, when HTTP keep-alive is enabled, using HTTP keywords in TCP inspection rules, and running with rewrite rules that appends to requests, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted pipelined HTTP requests that prevent request realignment from occurring.
Ubuntu
HAProxy vulnerabilities
vendor_ubuntu·2013-04-15·CVSS 5.1
CVE-2012-2942 [MEDIUM] HAProxy vulnerabilities
Title: HAProxy vulnerabilities
Summary: HAProxy could be made to crash or run programs if it received specially
crafted network traffic.
It was discovered that HAProxy incorrectly handled configurations where
global.tune.bufsize was set to a value higher than the default. A remote
attacker could use this issue to cause a denial of service, or possibly
execute arbitrary code. (CVE-2012-2942)
Yves Lafon discovered that HAProxy incorrectly handled HTTP keywords in TCP
inspection rules when HTTP keep-alive is enabled. A remote attacker could
use this issue to cause a denial of service, or possibly execute arbitrary
code. (CVE-2013-1912)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
haproxy: rewrite rules flaw can lead to arbitrary code execution
vendor_redhat·2013-04-02·CVSS 5.1
CVE-2013-1912 [MEDIUM] haproxy: rewrite rules flaw can lead to arbitrary code execution
haproxy: rewrite rules flaw can lead to arbitrary code execution
Buffer overflow in HAProxy 1.4 through 1.4.22 and 1.5-dev through 1.5-dev17, when HTTP keep-alive is enabled, using HTTP keywords in TCP inspection rules, and running with rewrite rules that appends to requests, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted pipelined HTTP requests that prevent request realignment from occurring.
Debian
CVE-2013-1912: haproxy - Buffer overflow in HAProxy 1.4 through 1.4.22 and 1.5-dev through 1.5-dev17, whe...
vendor_debian·2013·CVSS 5.1
CVE-2013-1912 [MEDIUM] CVE-2013-1912: haproxy - Buffer overflow in HAProxy 1.4 through 1.4.22 and 1.5-dev through 1.5-dev17, whe...
Buffer overflow in HAProxy 1.4 through 1.4.22 and 1.5-dev through 1.5-dev17, when HTTP keep-alive is enabled, using HTTP keywords in TCP inspection rules, and running with rewrite rules that appends to requests, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted pipelined HTTP requests that prevent request realignment from occurring.
Scope: local
bookworm: resolved (fixed in 1.4.23-1)
bullseye: resolved (fixed in 1.4.23-1)
forky: resolved (fixed in 1.4.23-1)
sid: resolved (fixed in 1.4.23-1)
trixie: resolved (fixed in 1.4.23-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1912 haproxy: rewrite rules flaw can lead to arbitrary code execution [fedora-all]
bugzilla·2013-04-03·CVSS 5.1
CVE-2013-1912 [MEDIUM] CVE-2013-1912 haproxy: rewrite rules flaw can lead to arbitrary code execution [fedora-all]
CVE-2013-1912 haproxy: rewrite rules flaw can lead to arbitrary code execution [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note:
Bugzilla
CVE-2013-1912 haproxy: rewrite rules flaw can lead to arbitrary code execution [epel-5]
bugzilla·2013-04-03·CVSS 5.1
CVE-2013-1912 [MEDIUM] CVE-2013-1912 haproxy: rewrite rules flaw can lead to arbitrary code execution [epel-5]
CVE-2013-1912 haproxy: rewrite rules flaw can lead to arbitrary code execution [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 track
Bugzilla
CVE-2013-1912 haproxy: rewrite rules flaw can lead to arbitrary code execution
bugzilla·2013-04-02·CVSS 5.1
CVE-2013-1912 [MEDIUM] CVE-2013-1912 haproxy: rewrite rules flaw can lead to arbitrary code execution
CVE-2013-1912 haproxy: rewrite rules flaw can lead to arbitrary code execution
Willy Tarreau reports:
we've discovered a vulnerability in haproxy when we use 'tcp-request
content rules which make use of some HTTP ACLs, combined with
keep-alive and request rewrite rules. A client making use of
pipelining could cause the rewrite rules to write past the buffer's
end because the reserved space is missing.
Discussion:
Willy Tarreau reports:
Hi,
Yves Lafon from the W3C reported some random crashes of haproxy with an
advanced configuration, that we finally considered was a security issue
as it could remotely be triggered.
--- summary ---
Configurations at risk are those which combine use of HTTP keywords in
TCP content inspection rules, client-side keep-alive, header rewriting
rules and
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/103730.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-April/103770.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-April/103794.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0729.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0868.htmlhttp://secunia.com/advisories/52725http://www.debian.org/security/2013/dsa-2711http://www.openwall.com/lists/oss-security/2013/04/03/1http://www.securityfocus.com/bid/58820http://www.ubuntu.com/usn/USN-1800-1http://lists.fedoraproject.org/pipermail/package-announce/2013-April/103730.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-April/103770.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-April/103794.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0729.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0868.htmlhttp://secunia.com/advisories/52725http://www.debian.org/security/2013/dsa-2711http://www.openwall.com/lists/oss-security/2013/04/03/1http://www.securityfocus.com/bid/58820http://www.ubuntu.com/usn/USN-1800-1
2013-04-10
Published