Re: About haproxy and CVE-2019-14241

2019-07-24 Thread Reco
Hi. On Wed, Jul 24, 2019 at 10:05:49AM +0200, Martin wrote: > I've received an advisory issued by one of my client's CERT. It is about > haproxy and CVE-2019-14241: > > "HAProxy contains a flaw in the htx_manage_client_side_cookies() function in > prot

About haproxy and CVE-2019-14241

2019-07-24 Thread Martin
Hi list, I've received an advisory issued by one of my client's CERT. It is about haproxy and CVE-2019-14241: "HAProxy contains a flaw in the htx_manage_client_side_cookies() function in proto_htx.c that is triggered when handling certain threads. This may allow a remote atta