PublicDateAtUSN: 2018-12-12 Candidate: CVE-2018-20102 PublicDate: 2018-12-12 17:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20102 https://ubuntu.com/security/notices/USN-3858-1 Description: An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14. Due to a missing check when validating DNS responses, remote attackers might be able read the 16 bytes corresponding to an AAAA record from the non-initialized part of the buffer, possibly accessing anything that was left on the stack, or even past the end of the 8193-byte buffer, depending on the value of accepted_payload_size. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=916308 Priority: medium Discovered-by: Assigned-to: leosilva CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N [7.5 HIGH] Patches_haproxy: upstream: http://git.haproxy.org/?p=haproxy.git;a=commit;h=efbbdf72992cd20458259962346044cafd9331c0 upstream_haproxy: released (1.8.15-1) precise/esm_haproxy: DNE trusty_haproxy: not-affected (code not present) trusty/esm_haproxy: DNE (trusty was not-affected [code not present]) xenial_haproxy: released (1.6.3-1ubuntu0.2) esm-infra/xenial_haproxy: released (1.6.3-1ubuntu0.2) bionic_haproxy: released (1.8.8-1ubuntu0.3) cosmic_haproxy: released (1.8.13-2ubuntu0.1) devel_haproxy: released (1.8.15-1)