cbcvebase.
CVE-2018-20103
published 2018-12-12

CVE-2018-20103: An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a crafted packet can trigger infinite recursion by making the…

high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a crafted packet can trigger infinite recursion by making the pointer point to itself, or create a long chain of valid pointers resulting in stack exhaustion.

Affected

12 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianhaproxy< haproxy 1.8.15-1 (bookworm)haproxy 1.8.15-1 (bookworm)
haproxyhaproxy<= 1.8.14
haproxyhaproxy>= 0 < 1.8.15-11.8.15-1
haproxyhaproxy>= 0 < 1.8.15-11.8.15-1
haproxyhaproxy>= 0 < 1.8.15-11.8.15-1
haproxyhaproxy>= 0 < 1.8.15-11.8.15-1
haproxyhaproxy>= 0 < 1.6.3-1ubuntu0.21.6.3-1ubuntu0.2
haproxyhaproxy>= 0 < 1.8.8-1ubuntu0.31.8.8-1ubuntu0.3
redhatopenshift_container_platform

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH