[ubuntu/quantal-security] haproxy 1.4.18-0ubuntu2.1 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Mon Apr 15 18:22:18 UTC 2013


haproxy (1.4.18-0ubuntu2.1) quantal-security; urgency=low

  * SECURITY UPDATE: denial of service and possible arbitrary code
    execution via non-default global.tune.bufsize.
    - debian/patches/CVE-2012-2942.patch: check buffer sizes in
      include/types/global.h, src/acl.c, src/cfgparse.c, src/checks.c,
      src/dumpstats.c, src/haproxy.c, src/proto_http.c,
      tests/0000-debug-stats.diff.
    - CVE-2012-2942
  * SECURITY UPDATE: denial of service via HTTP information in tcp-request
    - debian/patches/CVE-2013-1912.patch: properly handle buffers in
      src/proto_http.c.
    - CVE-2013-1912

Date: 2013-04-05 14:30:16.015554+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/quantal/+source/haproxy/1.4.18-0ubuntu2.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Quantal-changes mailing list