{"id":"SUSE-SU-2018:3249-1","summary":"Security update for haproxy","details":"This update for haproxy to version 1.8.14 fixes the following issues:\n\nThese security issues were fixed:\n\n- CVE-2018-14645: A flaw was discovered in the HPACK decoder what caused an\n  out-of-bounds read in hpack_valid_idx() that resulted in a remote crash and\n  denial of service (bsc#1108683)\n- CVE-2018-11469: Incorrect caching of responses to requests including an\n  Authorization header allowed attackers to achieve information disclosure via an\n  unauthenticated remote request (bsc#1094846).\n\nThese non-security issues were fixed:\n\n- Require apparmor-abstractions to reduce dependencies (bsc#1100787)\n- hpack: fix improper sign check on the header index value\n- cli: make sure the 'getsock' command is only called on connections\n- tools: fix set_net_port() / set_host_port() on IPv4\n- patterns: fix possible double free when reloading a pattern list\n- server: Crash when setting FQDN via CLI.\n- kqueue: Don't reset the changes number by accident.\n- snapshot: take the proxy's lock while dumping errors\n- http/threads: atomically increment the error snapshot ID\n- dns: check and link servers' resolvers right after config parsing\n- h2: fix risk of memory leak on malformated wrapped frames\n- session: fix reporting of handshake processing time in the logs\n- stream: use atomic increments for the request counter\n- thread: implement HA_ATOMIC_XADD()\n- ECC cert should work with TLS \u003c v1.2 and openssl \u003e= 1.1.1\n- dns/server: fix incomatibility between SRV resolution and server state file\n- hlua: Don't call RESET_SAFE_LJMP if SET_SAFE_LJMP returns 0.\n- thread: lua: Wrong SSL context initialization.\n- hlua: Make sure we drain the output buffer when done.\n- lua: reset lua transaction between http requests\n- mux_pt: dereference the connection with care in mux_pt_wake()\n- lua: Bad HTTP client request duration.\n- unix: provide a -\u003edrain() function\n- Fix spelling error in configuration doc\n- cli/threads: protect some server commands against concurrent operations\n- cli/threads: protect all 'proxy' commands against concurrent updates\n- lua: socket timeouts are not applied\n- ssl: Use consistent naming for TLS protocols\n- dns: explain set server ... fqdn requires resolver\n- map: fix map_regm with backref\n- ssl: loading dh param from certifile causes unpredictable error.\n- ssl: fix missing error loading a keytype cert from a bundle.\n- ssl: empty connections reported as errors.\n- cli: make 'show fd' thread-safe\n- hathreads: implement a more flexible rendez-vous point\n- threads: fix the no-thread case after the change to the sync point\n- threads: add more consistency between certain variables in no-thread case\n- threads: fix the double CAS implementation for ARMv7\n- threads: Introduce double-width CAS on x86_64 and arm.\n- lua: possible CLOSE-WAIT state with '\\n' headers\n\nFor additional changes please refer to the changelog.\n","modified":"2026-03-11T06:59:06.138790Z","published":"2018-10-19T12:59:02Z","related":["CVE-2018-11469","CVE-2018-14645"],"upstream":["CVE-2018-11469","CVE-2018-14645"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20183249-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1094846"},{"type":"REPORT","url":"https://bugzilla.suse.com/1100787"},{"type":"REPORT","url":"https://bugzilla.suse.com/1108683"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-11469"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-14645"}],"affected":[{"package":{"name":"haproxy","ecosystem":"SUSE:Linux Enterprise High Availability Extension 15","purl":"pkg:rpm/suse/haproxy&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.14~git0.52e4d43b-3.3.2"}]}],"ecosystem_specific":{"binaries":[{"haproxy":"1.8.14~git0.52e4d43b-3.3.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2018:3249-1.json"}}],"schema_version":"1.7.5"}