cbcvebase.
CVE-2013-1912
published 2013-04-10

CVE-2013-1912: Buffer overflow in HAProxy 1.4 through 1.4.22 and 1.5-dev through 1.5-dev17, when HTTP keep-alive is enabled, using HTTP keywords in TCP inspection rules, and…

PriorityP336medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
5.46%
91.9th percentile
Buffer overflow in HAProxy 1.4 through 1.4.22 and 1.5-dev through 1.5-dev17, when HTTP keep-alive is enabled, using HTTP keywords in TCP inspection rules, and running with rewrite rules that appends to requests, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted pipelined HTTP requests that prevent request realignment from occurring.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianhaproxy< haproxy 1.4.23-1 (bookworm)haproxy 1.4.23-1 (bookworm)
haproxyhaproxy
haproxyhaproxy
haproxyhaproxy
haproxyhaproxy
haproxyhaproxy>= 0 < 1.4.23-11.4.23-1
haproxyhaproxy>= 0 < 1.4.23-11.4.23-1
haproxyhaproxy>= 0 < 1.4.23-11.4.23-1
haproxyhaproxy>= 0 < 1.4.23-11.4.23-1

CVSS provenance

nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv5.1MEDIUM
vendor_debian5.1MEDIUM
vendor_redhat5.1MEDIUM
vendor_ubuntu5.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.