CVE-2012-2942
haproxy - several
EPSS 5.4%
描述
Buffer overflow in the trash buffer in the header capture functionality in HAProxy before 1.4.21, when global.tune.bufsize is set to a value greater than the default and header rewriting is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors.
如何修補 CVE-2012-2942
要修補 CVE-2012-2942,請將受影響套件升級到下列已修補版本。
- Debian/haproxy—升級至 1.4.23-1 或更新版本
- Debian/haproxy—升級至 1.4.8-1+squeeze1 或更新版本
CVE-2012-2942 正在被利用嗎?
中等 — EPSS 為 5.4%,可持續追蹤但非最高優先。
受影響套件(2)
- from 0, < 1.4.23-1
- from 0, < 1.4.8-1+squeeze1