CVE-2015-3281

CWE-119Buffer Overflow9 documents8 sources
Severity
5.0MEDIUM
EPSS
0.1%
top 73.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 6
Latest updateMay 14

Description

The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of previous requests) via a crafted request.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages8 packages

Debianhaproxy< 1.5.14-1+3
NVDhaproxy/haproxy16 versions+15

Also affects: Debian Linux 8.0, Ubuntu Linux 14.10, 15.04, Enterprise Linux 7.3, 7.4, 7.6, 7.1, 7.2, 7.5

Patches

🔴Vulnerability Details

3
GHSA
GHSA-ffg4-hmhr-qr79: The buffer_slow_realign function in HAProxy 12022-05-14
CVEList
CVE-2015-3281: The buffer_slow_realign function in HAProxy 12015-07-06
OSV
CVE-2015-3281: The buffer_slow_realign function in HAProxy 12015-07-06

📋Vendor Advisories

3
Red Hat
haproxy: information leak in buffer_slow_realign()2015-07-07
Ubuntu
HAProxy vulnerability2015-07-07
Debian
CVE-2015-3281: haproxy - The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does...2015

💬Community

2
Bugzilla
CVE-2015-3281 haproxy: information leak in buffer_slow_realign() [fedora-all]2015-07-08
Bugzilla
CVE-2015-3281 haproxy: information leak in buffer_slow_realign()2015-07-03
CVE-2015-3281 (MEDIUM CVSS 5) | The buffer_slow_realign function in | cvebase.io