NASLDB: HAProxy Trash Buffer Overflow Vulnerability
General
ID: 59798
Name: HAProxy Trash Buffer Overflow Vulnerability
Summary: Checks version of HAProxy
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: –
CVSS Base Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:P
CVSS Temporal Vector: CVSS2#E:U/RL:OF/RC:C
Port: 8080
Family: Misc.
Type: Remote
Description
Based on the self reported version obtained from the HAProxy
statistics reporting page, the remote host is running load balancing
software that is potentially affected by a buffer overflow
vulnerability when copying data into the trash buffer.
It may be possible for an attacker to exploit this vulnerability to
execute arbitrary code on the remote host, but it requires that the
global.tune.bufsize option is set to a value greater than default and
that header rewriting is configured.
Exploiting
Exploit Available: False
Exploitability Ease: No known exploits are available
Sources
CVE: CVE-2012-2942
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: 2012/05/16
Patch Release: 2012/05/21
Plugin Release: 2012/06/29
Plugin
Version: 1.2
Filename: haproxy_trash_buffer_overflow.nasl
Filesize: 3995 bytes
MD5 Hash: 4fd162159dfa867443e581b66231687f
Identification: –
Require Keys: www/haproxy_stats_page", "Settings/ParanoidReport
Dependencies: "haproxy_statspage_detect.nasl"
Copyright: This script is Copyright© 2012 Tenable Network Security, Inc.
- Letzte Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













