{"affected":[{"ecosystem_specific":{"binaries":[{"haproxy":"1.8.14~git0.52e4d43b-3.3.2"}]},"package":{"ecosystem":"SUSE:Linux Enterprise High Availability Extension 15","name":"haproxy","purl":"pkg:rpm/suse/haproxy&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.8.14~git0.52e4d43b-3.3.2"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for haproxy to version 1.8.14 fixes the following issues:\n\nThese security issues were fixed:\n\n- CVE-2018-14645: A flaw was discovered in the HPACK decoder what caused an\n  out-of-bounds read in hpack_valid_idx() that resulted in a remote crash and\n  denial of service (bsc#1108683)\n- CVE-2018-11469: Incorrect caching of responses to requests including an\n  Authorization header allowed attackers to achieve information disclosure via an\n  unauthenticated remote request (bsc#1094846).\n\nThese non-security issues were fixed:\n\n- Require apparmor-abstractions to reduce dependencies (bsc#1100787)\n- hpack: fix improper sign check on the header index value\n- cli: make sure the 'getsock' command is only called on connections\n- tools: fix set_net_port() / set_host_port() on IPv4\n- patterns: fix possible double free when reloading a pattern list\n- server: Crash when setting FQDN via CLI.\n- kqueue: Don't reset the changes number by accident.\n- snapshot: take the proxy's lock while dumping errors\n- http/threads: atomically increment the error snapshot ID\n- dns: check and link servers' resolvers right after config parsing\n- h2: fix risk of memory leak on malformated wrapped frames\n- session: fix reporting of handshake processing time in the logs\n- stream: use atomic increments for the request counter\n- thread: implement HA_ATOMIC_XADD()\n- ECC cert should work with TLS < v1.2 and openssl >= 1.1.1\n- dns/server: fix incomatibility between SRV resolution and server state file\n- hlua: Don't call RESET_SAFE_LJMP if SET_SAFE_LJMP returns 0.\n- thread: lua: Wrong SSL context initialization.\n- hlua: Make sure we drain the output buffer when done.\n- lua: reset lua transaction between http requests\n- mux_pt: dereference the connection with care in mux_pt_wake()\n- lua: Bad HTTP client request duration.\n- unix: provide a ->drain() function\n- Fix spelling error in configuration doc\n- cli/threads: protect some server commands against concurrent operations\n- cli/threads: protect all 'proxy' commands against concurrent updates\n- lua: socket timeouts are not applied\n- ssl: Use consistent naming for TLS protocols\n- dns: explain set server ... fqdn requires resolver\n- map: fix map_regm with backref\n- ssl: loading dh param from certifile causes unpredictable error.\n- ssl: fix missing error loading a keytype cert from a bundle.\n- ssl: empty connections reported as errors.\n- cli: make 'show fd' thread-safe\n- hathreads: implement a more flexible rendez-vous point\n- threads: fix the no-thread case after the change to the sync point\n- threads: add more consistency between certain variables in no-thread case\n- threads: fix the double CAS implementation for ARMv7\n- threads: Introduce double-width CAS on x86_64 and arm.\n- lua: possible CLOSE-WAIT state with '\\n' headers\n\nFor additional changes please refer to the changelog.\n","id":"SUSE-SU-2018:3249-1","modified":"2018-10-19T12:59:02Z","published":"2018-10-19T12:59:02Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20183249-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1094846"},{"type":"REPORT","url":"https://bugzilla.suse.com/1100787"},{"type":"REPORT","url":"https://bugzilla.suse.com/1108683"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-11469"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-14645"}],"related":["CVE-2018-11469","CVE-2018-14645"],"summary":"Security update for haproxy","upstream":["CVE-2018-11469","CVE-2018-14645"]}