CVE-2014-6269
Published Sep 30, 2014
Last updated a year ago
Overview
- Description
- Multiple integer overflows in the http_request_forward_body function in proto_http.c in HAProxy 1.5-dev23 before 1.5.4 allow remote attackers to cause a denial of service (crash) via a large stream of data, which triggers a buffer overflow and an out-of-bounds read.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:N/A:P
Weaknesses
- nvd@nist.gov
- CWE-189
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:haproxy:haproxy:1.5:dev23:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "102F3A11-6B72-4A17-94D9-C42BD64B5938" }, { "criteria": "cpe:2.3:a:haproxy:haproxy:1.5:dev24:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7E806EB6-3E27-4C0C-9108-58E1A58B7C0C" }, { "criteria": "cpe:2.3:a:haproxy:haproxy:1.5:dev25:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6A8EC32E-8A94-4952-AF27-68D0309DF1DA" }, { "criteria": "cpe:2.3:a:haproxy:haproxy:1.5:dev26:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3F1D7768-3ECC-4E3A-998E-F471274CB7F1" }, { "criteria": "cpe:2.3:a:haproxy:haproxy:1.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A8346999-B3EE-4BBA-ABEA-F9D07017EBAC" }, { "criteria": "cpe:2.3:a:haproxy:haproxy:1.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4DD95164-7653-4433-97AB-8D0BA0B89828" }, { "criteria": "cpe:2.3:a:haproxy:haproxy:1.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CA2EA9FE-BCD8-483D-91B2-FCDD096E9F68" }, { "criteria": "cpe:2.3:a:haproxy:haproxy:1.5.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BBF8DB5D-B3DC-4EAC-A3A7-06846615980A" } ], "operator": "OR" } ] } ]