{"id":"UBUNTU-CVE-2015-3281","details":"The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of previous requests) via a crafted request.","modified":"2026-01-30T01:18:21.162852Z","published":"2015-07-06T00:00:00Z","withdrawn":"2025-07-18T16:43:12Z","related":["USN-2668-1"],"upstream":["CVE-2015-3281"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2015-3281"},{"type":"REPORT","url":"http://www.haproxy.org/news.html"},{"type":"REPORT","url":"http://www.debian.org/security/2015/dsa-3301"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-2668-1"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2015-3281"}],"affected":[{"package":{"name":"haproxy","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/haproxy@1.4.24-2?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.24-2"}]}],"versions":["1.4.24-1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"haproxy","binary_version":"1.4.24-2"},{"binary_name":"vim-haproxy","binary_version":"1.4.24-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2015/UBUNTU-CVE-2015-3281.json"}}],"schema_version":"1.7.3","severity":[{"type":"Ubuntu","score":"medium"}]}