cbcvebase.
CVE-2020-11100
published 2020-04-02

CVE-2020-11100: In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.

Affected

14 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianhaproxy< haproxy 2.0.13-2 (bookworm)haproxy 2.0.13-2 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
haproxyhaproxy>= 0 < 2.0.13-22.0.13-2
haproxyhaproxy>= 0 < 2.0.13-22.0.13-2
haproxyhaproxy>= 0 < 2.0.13-22.0.13-2
haproxyhaproxy>= 0 < 2.0.13-22.0.13-2
haproxyhaproxy>= 1.8.0 < 2.1.42.1.4
opensuseleap
redhatopenshift_container_platform
redhatopenshift_container_platform

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH