CVE-2015-3281
published 2015-07-06CVE-2015-3281: The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which…
PriorityP426medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
4.27%
90.0th percentile
The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of previous requests) via a crafted request.
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | haproxy | < haproxy 1.5.14-1 (bookworm) | haproxy 1.5.14-1 (bookworm) |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | — | — |
| haproxy | haproxy | >= 0 < 1.5.14-1 | 1.5.14-1 |
| haproxy | haproxy | >= 0 < 1.5.14-1 | 1.5.14-1 |
| haproxy | haproxy | >= 0 < 1.5.14-1 | 1.5.14-1 |
| haproxy | haproxy | >= 0 < 1.5.14-1 | 1.5.14-1 |
| opensuse | openstack_cloud | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ffg4-hmhr-qr79: The buffer_slow_realign function in HAProxy 1
ghsa_unreviewed·2022-05-14
CVE-2015-3281 [MEDIUM] CWE-119 GHSA-ffg4-hmhr-qr79: The buffer_slow_realign function in HAProxy 1
The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of previous requests) via a crafted request.
OSV
CVE-2015-3281: The buffer_slow_realign function in HAProxy 1
osv·2015-07-06·CVSS 5.0
CVE-2015-3281 [MEDIUM] CVE-2015-3281: The buffer_slow_realign function in HAProxy 1
The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of previous requests) via a crafted request.
Red Hat
haproxy: information leak in buffer_slow_realign()
vendor_redhat·2015-07-07·CVSS 5.0
CVE-2015-3281 [MEDIUM] CWE-119 haproxy: information leak in buffer_slow_realign()
haproxy: information leak in buffer_slow_realign()
The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of previous requests) via a crafted request.
An implementation error related to the memory management of request and responses was found within HAProxy's buffer_slow_realign() function. An unauthenticated remote attacker could possibly use this flaw to leak certain memory buffer contents from a past request or session.
Package: haproxy (Red Hat OpenShift Enterprise 2) - Not affected
Ubuntu
HAProxy vulnerability
vendor_ubuntu·2015-07-07
CVE-2015-3281 HAProxy vulnerability
Title: HAProxy vulnerability
Summary: HAProxy could be made to expose sensitive information over the network.
It was discovered that HAProxy incorrectly handled certain buffers. A
remote attacker could possibly use this issue to obtain sensitive
information belonging to previous requests.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2015-3281: haproxy - The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does...
vendor_debian·2015·CVSS 5.0
CVE-2015-3281 [MEDIUM] CVE-2015-3281: haproxy - The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does...
The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of previous requests) via a crafted request.
Scope: local
bookworm: resolved (fixed in 1.5.14-1)
bullseye: resolved (fixed in 1.5.14-1)
forky: resolved (fixed in 1.5.14-1)
sid: resolved (fixed in 1.5.14-1)
trixie: resolved (fixed in 1.5.14-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-3281 haproxy: information leak in buffer_slow_realign() [fedora-all]
bugzilla·2015-07-08·CVSS 5.0
CVE-2015-3281 [MEDIUM] CVE-2015-3281 haproxy: information leak in buffer_slow_realign() [fedora-all]
CVE-2015-3281 haproxy: information leak in buffer_slow_realign() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2015-3281 haproxy: information leak in buffer_slow_realign()
bugzilla·2015-07-03·CVSS 5.0
CVE-2015-3281 [MEDIUM] CVE-2015-3281 haproxy: information leak in buffer_slow_realign()
CVE-2015-3281 haproxy: information leak in buffer_slow_realign()
Information disclosure vulnerability was reported in HAproxy.
Details (quoting attached patch):
The function buffer_slow_realign() was initially designed for requests
only and did not consider pending outgoing data. This causes a problem
when called on responses where data remain in the buffer, which may
happen with pipelined requests when the client is slow to read data.
The user-visible effect is that if less than bytes are
present in the buffer from a previous response and these bytes cross
the boundary close to the end of the buffer, then a new
response will cause a realign and will destroy these pending data and
move the pointer to what's believed to contain pending output data.
Thus the client receives the crap that
http://git.haproxy.org/?p=haproxy-1.5.git%3Ba=commit%3Bh=7ec765568883b2d4e5a2796adbeb492a22ec9bd4http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-10/msg00023.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1741.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2666.htmlhttp://www.debian.org/security/2015/dsa-3301http://www.haproxy.org/news.htmlhttp://www.securityfocus.com/bid/75554http://www.ubuntu.com/usn/USN-2668-1http://git.haproxy.org/?p=haproxy-1.5.git%3Ba=commit%3Bh=7ec765568883b2d4e5a2796adbeb492a22ec9bd4http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-10/msg00023.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1741.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2666.htmlhttp://www.debian.org/security/2015/dsa-3301http://www.haproxy.org/news.htmlhttp://www.securityfocus.com/bid/75554http://www.ubuntu.com/usn/USN-2668-1
2015-07-06
Published