CVE-2013-2175
published 2013-08-19CVE-2013-2175: HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows remote…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.52%
88.0th percentile
HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows remote attackers to cause a denial of service (negative array index usage and crash) via an HTTP header with a certain number of values, related to the MAX_HDR_HISTORY variable.
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | haproxy | < haproxy 1.4.24-1 (bookworm) | haproxy 1.4.24-1 (bookworm) |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4wh9-9j6m-2gcq: HAProxy 1
ghsa_unreviewed·2022-05-17
CVE-2013-2175 [MEDIUM] CWE-20 GHSA-4wh9-9j6m-2gcq: HAProxy 1
HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows remote attackers to cause a denial of service (negative array index usage and crash) via an HTTP header with a certain number of values, related to the MAX_HDR_HISTORY variable.
OSV
CVE-2013-2175: HAProxy 1
osv·2013-08-19·CVSS 5.0
CVE-2013-2175 [MEDIUM] CVE-2013-2175: HAProxy 1
HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows remote attackers to cause a denial of service (negative array index usage and crash) via an HTTP header with a certain number of values, related to the MAX_HDR_HISTORY variable.
Ubuntu
HAProxy vulnerability
vendor_ubuntu·2013-06-20
CVE-2013-2175 HAProxy vulnerability
Title: HAProxy vulnerability
Summary: HAProxy could be made to crash if it received specially crafted network
traffic.
David Torgerson discovered that HAProxy incorrectly parsed certain HTTP
headers. A remote attacker could use this issue to cause HAProxy to stop
responding, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
haproxy: http_get_hdr()/get_ip_from_hdr2() MAX_HDR_HISTORY handling denial of service
vendor_redhat·2013-06-17·CVSS 5.0
CVE-2013-2175 [MEDIUM] haproxy: http_get_hdr()/get_ip_from_hdr2() MAX_HDR_HISTORY handling denial of service
haproxy: http_get_hdr()/get_ip_from_hdr2() MAX_HDR_HISTORY handling denial of service
HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows remote attackers to cause a denial of service (negative array index usage and crash) via an HTTP header with a certain number of values, related to the MAX_HDR_HISTORY variable.
Debian
CVE-2013-2175: haproxy - HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_i...
vendor_debian·2013·CVSS 5.0
CVE-2013-2175 [MEDIUM] CVE-2013-2175: haproxy - HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_i...
HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows remote attackers to cause a denial of service (negative array index usage and crash) via an HTTP header with a certain number of values, related to the MAX_HDR_HISTORY variable.
Scope: local
bookworm: resolved (fixed in 1.4.24-1)
bullseye: resolved (fixed in 1.4.24-1)
forky: resolved (fixed in 1.4.24-1)
sid: resolved (fixed in 1.4.24-1)
trixie: resolved (fixed in 1.4.24-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2175 haproxy: http_get_hdr()/get_ip_from_hdr2() MAX_HDR_HISTORY handling denial of service [fedora-all]
bugzilla·2013-06-17·CVSS 5.0
CVE-2013-2175 [MEDIUM] CVE-2013-2175 haproxy: http_get_hdr()/get_ip_from_hdr2() MAX_HDR_HISTORY handling denial of service [fedora-all]
CVE-2013-2175 haproxy: http_get_hdr()/get_ip_from_hdr2() MAX_HDR_HISTORY handling denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when avai
Bugzilla
CVE-2013-2175 haproxy: http_get_hdr()/get_ip_from_hdr2() MAX_HDR_HISTORY handling denial of service
bugzilla·2013-06-13·CVSS 5.0
CVE-2013-2175 [MEDIUM] CVE-2013-2175 haproxy: http_get_hdr()/get_ip_from_hdr2() MAX_HDR_HISTORY handling denial of service
CVE-2013-2175 haproxy: http_get_hdr()/get_ip_from_hdr2() MAX_HDR_HISTORY handling denial of service
Willy Tarreau ([email protected]) reports:
Hi all,
a reproducible crash on latest haproxy snapshots was recently reported,
and could finally be tracked down to a serious bug affecting all versions
since 1.4.4.
The bug is in http_get_hdr() in haproxy 1.5, or get_ip_from_hdr2() in
haproxy 1.4. If a configuration makes use of one of the following functions :
- hdr_ip(, ) (in 1.4)
- hdr_*(, ) (in 1.5)
with a negative , then the configuration risks to crash when the
request contains exactly MAX_HDR_HISTORY values for the header .
Note: "source 0.0.0.0 usesrc hdr_ip()" uses -1 by default for
and is vulnerable as well !
The quick workaround I can suggest before patching is to reject dangerous
reques
http://marc.info/?l=haproxy&m=137147915029705&w=2http://rhn.redhat.com/errata/RHSA-2013-1120.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1204.htmlhttp://secunia.com/advisories/54344http://www.debian.org/security/2013/dsa-2711http://www.ubuntu.com/usn/USN-1889-1https://bugzilla.redhat.com/show_bug.cgi?id=974259http://marc.info/?l=haproxy&m=137147915029705&w=2http://rhn.redhat.com/errata/RHSA-2013-1120.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1204.htmlhttp://secunia.com/advisories/54344http://www.debian.org/security/2013/dsa-2711http://www.ubuntu.com/usn/USN-1889-1https://bugzilla.redhat.com/show_bug.cgi?id=974259
2013-08-19
Published