PublicDateAtUSN: 2018-12-31 Candidate: CVE-2018-20615 PublicDate: 2019-03-21 16:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20615 https://ubuntu.com/security/notices/USN-3858-1 Description: An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a crash. The processing of the PRIORITY flag in a HEADERS frame requires 5 extra bytes, and while these bytes are skipped, the total frame length was not re-checked to make sure they were present in the frame. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: leosilva CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_haproxy: upstream: https://github.com/haproxy/haproxy/commit/a01f45e3ced23c799f6e78b5efdbd32198a75354 upstream_haproxy: released (1.8.16-2) precise/esm_haproxy: DNE trusty_haproxy: not-affected (code not present) trusty/esm_haproxy: DNE (trusty was not-affected [code not present]) xenial_haproxy: not-affected (code not present) esm-infra/xenial_haproxy: not-affected (code not present) bionic_haproxy: released (1.8.8-1ubuntu0.3) cosmic_haproxy: released (1.8.13-2ubuntu0.1) devel_haproxy: released (1.8.17-1)