CVE-2020-11100 — Out-of-bounds Write in Haproxy
Severity
8.8HIGHNVD
EPSS
74.8%
top 1.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 2
Latest updateMay 24
Description
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages3 packages
Also affects: Debian Linux 10.0, Fedora 30, 31, Ubuntu Linux 18.04, 19.10, Openshift Container Platform 3.11, 4.0