CVE-2013-2175 Information
Feb 14, 2021
cve
Description
HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19 when configured to use hdr_ip or other \hdr_*\ functions with a negative occurrence count allows remote attackers to cause a denial of service (negative array index usage and crash) via an HTTP header with a certain number of values related to the MAX_HDR_HISTORY variable.
Reference
http://marc.info/?l=haproxy&m=137147915029705&w=2 http://rhn.redhat.com/errata/RHSA-2013-1120.html http://rhn.redhat.com/errata/RHSA-2013-1204.html http://secunia.com/advisories/54344 http://www.debian.org/security/2013/dsa-2711 http://www.ubuntu.com/usn/USN-1889-1 https://bugzilla.redhat.com/show_bug.cgi?id=974259
Share on: