CVE-2015-3281
Severity
5.0MEDIUM
EPSS
0.1%
top 73.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 6
Latest updateMay 14
Description
The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of previous requests) via a crafted request.
CVSS vector
AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9
Affected Packages8 packages
Also affects: Debian Linux 8.0, Ubuntu Linux 14.10, 15.04, Enterprise Linux 7.3, 7.4, 7.6, 7.1, 7.2, 7.5