Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 522018 - net-proxy/haproxy: remote client denial of service vulnerability (CVE-2014-6269)
Summary: net-proxy/haproxy: remote client denial of service vulnerability (CVE-2014-6269)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2014-09-03 07:29 UTC by Agostino Sarubbo
Modified: 2014-11-03 15:50 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2014-09-03 07:29:35 UTC
From ${URL} :

A denial of service vulnerability was reported [1],[2] in HAProxy 1.5dev23 through to and including 
1.5.3, and 1.6-dev.  A remote client could cause the HAProxy service to crash in specific 
conditions with a certain amount of server complicity (it must accept and slowly drain more than 
2GB of data).  There is no possibility of code execution or loss of data integrity.

This is corrected in upstream version 1.5.4 [3].

[1] http://article.gmane.org/gmane.comp.web.haproxy/17726
[2] http://article.gmane.org/gmane.comp.web.haproxy/18097
[3] 
http://git.haproxy.org/?p=haproxy-1.5.git;a=commitdiff;h=b4d05093bc89f71377230228007e69a1434c1a0c


@maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Comment 1 Christian Ruppert (idl0r) gentoo-dev 2014-09-03 17:49:04 UTC
All affected version were in testing. There's nothing to stabilize. Affected version(s) have been removed.
Comment 2 Kristian Fiskerstrand (RETIRED) gentoo-dev 2014-09-03 17:53:55 UTC
(In reply to Christian Ruppert (idl0r) from comment #1)
> All affected version were in testing. There's nothing to stabilize. Affected
> version(s) have been removed.

Thanks. 

Updating whiteboard rating to affect the non-stable state since this was indeed introduced in 1.5 series and closing as noglsa.
Comment 3 GLSAMaker/CVETool Bot gentoo-dev 2014-11-03 15:50:24 UTC
CVE-2014-6269 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-6269):
  Multiple integer overflows in the http_request_forward_body function in
  proto_http.c in HAProxy 1.5-dev23 before 1.5.4 allow remote attackers to
  cause a denial of service (crash) via a large stream of data, which triggers
  a buffer overflow and an out-of-bounds read.