CVE Database
/

CVE-2013-2175

Back to search

CVE-2013-2175

Published: Aug 19, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows remote attackers to cause a denial of service (negative array index usage and crash) via an HTTP header with a certain number of values, related to the MAX_HDR_HISTORY variable.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2013:1204
vendor-advisory
x_refsource_REDHAT
54344
third-party-advisory
x_refsource_SECUNIA
DSA-2711
vendor-advisory
x_refsource_DEBIAN
RHSA-2013:1120
vendor-advisory
x_refsource_REDHAT
USN-1889-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now