VDB
CVE-2012-2942
CVE-2012-2942
PUBLISHED
CVSS 5.099999904632568 MEDIUM
Buffer overflow in the trash buffer in the header capture functionality in HAProxy before 1.4.21, when global.tune.bufsize is set to a value greater than the default and header rewriting is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors.
EPSS 5.41% · 92.2th percentile
Risk Scores
CVSS 2.0
5.099999904632568
EPSS Score
5.41%
92.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| haproxy | haproxy | 0 |
| n/a | n/a | n/a |
Timeline
- May 27, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- http://haproxy.1wt.eu/#news url
- http://haproxy.1wt.eu/download/1.4/src/CHANGELOG url
- GLSA-201301-02 vendor-advisory
- 53647 vdb
- DSA-2711 vendor-advisory
- USN-1800-1 vendor-advisory
- http://haproxy.1wt.eu/git?p=haproxy-1.4.git%3Ba=commit%3Bh=30297cb17147a8d339eb160226bcc08c91d9530b url
- [oss-security] 20120523 CVE request: haproxy trash buffer overflow flaw mailing-list
- http://secunia.com/advisories/49261 advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/75777 technical
- http://www.openwall.com/lists/oss-security/2012/05/23/15 technical
- http://www.openwall.com/lists/oss-security/2012/05/28/1 technical
- https://nvd.nist.gov/vuln/detail/CVE-2012-2942 advisory
- http://haproxy.1wt.eu/git?p=haproxy-1.4.git;a=commit;h=30297cb17147a8d339eb160226bcc08c91d9530b url