#VU17107 Out-of-bounds read in HAProxy - CVE-2018-20615
Published: January 22, 2019
HAProxy
HAProxy
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to incorrect frame length validation when processing headers with priority flags set. A remote attacker can send a specially crafted HTTP/2 request, trigger our-of-bounds read and crash the affected application.