[ubuntu/oneiric-security] haproxy 1.4.15-1ubuntu0.1 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Mon Apr 15 18:22:19 UTC 2013

haproxy (1.4.15-1ubuntu0.1) oneiric-security; urgency=low

  * SECURITY UPDATE: denial of service and possible arbitrary code
    execution via non-default global.tune.bufsize.
    - debian/patches/CVE-2012-2942.patch: check buffer sizes in
      include/types/global.h, src/acl.c, src/cfgparse.c, src/checks.c,
      src/dumpstats.c, src/haproxy.c, src/proto_http.c,
    - CVE-2012-2942
  * SECURITY UPDATE: denial of service via HTTP information in tcp-request
    - debian/patches/CVE-2013-1912.patch: properly handle buffers in
    - CVE-2013-1912

Date: 2013-04-05 14:30:19.919378+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
-------------- next part --------------
Sorry, changesfile not available.

More information about the Oneiric-changes mailing list