HAProxy 'dns.c' Stack Exhaustion Denial Of Service Vulnerability
BID:106280
CVE-2018-20103 |Info
HAProxy 'dns.c' Stack Exhaustion Denial Of Service Vulnerability
| Bugtraq ID: | 106280 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2018-20103 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Dec 12 2018 12:00AM |
| Updated: | Dec 12 2018 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Redhat Software Collections for RHEL 0 Redhat OpenShift Container Platform 3.9 Redhat OpenShift Container Platform 3.7 Redhat OpenShift Container Platform 3.11 Redhat OpenShift Container Platform 3.10 haproxy haproxy 1.8.14 haproxy haproxy 1.8.9 haproxy haproxy 1.8 haproxy haproxy 1.7 haproxy haproxy 1.6.6 haproxy haproxy 1.6.5 haproxy haproxy 1.6.4 haproxy haproxy 1.6.3 haproxy haproxy 1.6.2 haproxy haproxy 1.6.1 haproxy haproxy 1.6 haproxy haproxy 1.5.4 haproxy haproxy 1.4.24 haproxy haproxy 1.4.23 haproxy haproxy 1.4.22 haproxy haproxy 1.4.21 haproxy haproxy 1.4.20 haproxy haproxy 1.4.15 haproxy haproxy 1.4.10 haproxy haproxy 1.4.9 haproxy haproxy 1.4.4 haproxy haproxy 1.5.14 haproxy haproxy 1.5-dev19 haproxy haproxy 1.5-dev18 haproxy haproxy 1.5 Dev9 haproxy haproxy 1.5 Dev8 haproxy haproxy 1.5 Dev7 haproxy haproxy 1.5 Dev6 haproxy haproxy 1.5 Dev5 haproxy haproxy 1.5 Dev4 haproxy haproxy 1.5 Dev3 haproxy haproxy 1.5 Dev2 haproxy haproxy 1.5 Dev19 haproxy haproxy 1.5 Dev18 haproxy haproxy 1.5 Dev17 haproxy haproxy 1.5 Dev16 haproxy haproxy 1.5 Dev15 haproxy haproxy 1.5 Dev14 haproxy haproxy 1.5 Dev13 haproxy haproxy 1.5 Dev12 haproxy haproxy 1.5 Dev11 haproxy haproxy 1.5 Dev10 haproxy haproxy 1.5 Dev1 haproxy haproxy 1.5 Dev0 haproxy haproxy 1.5 Dev haproxy haproxy 1.5 haproxy haproxy 1.4.8 haproxy haproxy 1.4.7 haproxy haproxy 1.4.6 haproxy haproxy 1.4.5 haproxy haproxy 1.4.3 haproxy haproxy 1.4.2 haproxy haproxy 1.4.19 haproxy haproxy 1.4.18 haproxy haproxy 1.4.17 haproxy haproxy 1.4.16 haproxy haproxy 1.4.14 haproxy haproxy 1.4.13 haproxy haproxy 1.4.12 haproxy haproxy 1.4.11 haproxy haproxy 1.4.1 haproxy haproxy 1.4.0 haproxy haproxy 1.4 |
| Not Vulnerable: |
haproxy haproxy 1.8.15 |
Discussion
HAProxy 'dns.c' Stack Exhaustion Denial Of Service Vulnerability
HAProxy is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to cause denial-of-service condition, denying service to legitimate users.
HAProxy 1.8.14 and prior versions are vulnerable.
HAProxy is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to cause denial-of-service condition, denying service to legitimate users.
HAProxy 1.8.14 and prior versions are vulnerable.
Solution / Fix
HAProxy 'dns.c' Stack Exhaustion Denial Of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
HAProxy 'dns.c' Stack Exhaustion Denial Of Service Vulnerability
References:
References:
- HAProxy Home Page (HAProxy)
- HAProxy Product Page (HAProxy)
- CVE-2018-20103 haproxy: Infinite recursion via crafted packet allows stack exhau (Redhat)
- Red Hat Bugzilla �?? Bug 1658876 (Red Hat Bugzilla)