← Back

CVE-2015-3281

nvd nist
Published: Jul 6, 2015Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of previous requests) via a crafted request.

Affected (56)

Show all products
1 product
Debian Linux
1 product
Haproxy
1 product
Ubuntu Linux
2 products
Openstack Cloud
Opensuse
1 product
6 products
Enterprise Linux Desktop
Enterprise Linux Server
Enterprise Linux Server Aus
Enterprise Linux Server Eus
Enterprise Linux Server Tus
Enterprise Linux Workstation
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Configuration B
36 vulnerable
Vulnerable SoftwareAffected Versions
Haproxy
Version 1.5.0
Version 1.5.10
Version 1.5.11
Version 1.5.12
Version 1.5.13
Version 1.5.1
Version 1.5.2
Version 1.5.3
Version 1.5.4
Version 1.5.5
Version 1.5.6
Version 1.5.7
Version 1.5.8
Version 1.5.9
Version 1.5 dev0
Version 1.5 dev10
Version 1.5 dev11
Version 1.5 dev12
Version 1.5 dev13
Version 1.5 dev14
Version 1.5 dev15
Version 1.5 dev16
Version 1.5 dev17
Version 1.5 dev18
Version 1.5 dev19
Version 1.5 dev1
Version 1.5 dev2
Version 1.5 dev3
Version 1.5 dev4
Version 1.5 dev5
Version 1.5 dev6
Version 1.5 dev7
Version 1.5 dev8
Version 1.5 dev9
Version 1.5 dev
Version 1.6 dev0
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 14.10
Version 15.04
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
Version 5
Version 13.2
Version 12
Configuration E
14 vulnerable

References (18)

Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
PatchVendor Advisory
Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.