CVE-2013-2175
haproxy: http_get_hdr()/get_ip_from_hdr2() MAX_HDR_HISTORY handling denial of service
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows remote attackers to cause a denial of service (negative array index usage and crash) via an HTTP header with a certain number of values, related to the MAX_HDR_HISTORY variable.
HAProxy 1.4 anteiror a 1.4.24 y 1.5 anteiror a 1.5-dev19, cuando es configurado para usar el hdr_ip u otras funciones "hdr_*" con una cuenta de ocurrencia negativa, permite a atacantes remotos provocar una denegación de servicio (uso de indexación negativa de array y caída) a través de una cabecera HTTP con un número determinado de valores. Relacionado con la variable MAX_HDR_HISTORY.
HAProxy provides high availability, load balancing, and proxying for TCP and HTTP-based applications. A flaw was found in the way HAProxy handled requests when the proxy's configuration had certain rules that use the hdr_ip criterion. A remote attacker could use this flaw to crash HAProxy instances that use the affected configuration. In Red Hat OpenShift Enterprise, the HAProxy cartridge is added to your application when you select to have your application scaled.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-02-19 CVE Reserved
- 2013-06-20 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
- CWE-284: Improper Access Control
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/54344 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://marc.info/?l=haproxy&m=137147915029705&w=2 | 2016-12-07 |
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2013-1120.html | 2016-12-07 | |
http://rhn.redhat.com/errata/RHSA-2013-1204.html | 2016-12-07 | |
http://www.debian.org/security/2013/dsa-2711 | 2016-12-07 | |
http://www.ubuntu.com/usn/USN-1889-1 | 2016-12-07 | |
https://bugzilla.redhat.com/show_bug.cgi?id=974259 | 2013-09-04 | |
https://access.redhat.com/security/cve/CVE-2013-2175 | 2013-09-04 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 6.0 Search vendor "Debian" for product "Debian Linux" and version "6.0" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 12.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "12.04" | lts |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 12.10 Search vendor "Canonical" for product "Ubuntu Linux" and version "12.10" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 13.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "13.04" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Load Balancer Search vendor "Redhat" for product "Enterprise Linux Load Balancer" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Load Balancer" and version "6.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Load Balancer Search vendor "Redhat" for product "Enterprise Linux Load Balancer" | 6.4 Search vendor "Redhat" for product "Enterprise Linux Load Balancer" and version "6.4" | - |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.4 Search vendor "Haproxy" for product "Haproxy" and version "1.4" | - |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.4.0 Search vendor "Haproxy" for product "Haproxy" and version "1.4.0" | - |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.4.1 Search vendor "Haproxy" for product "Haproxy" and version "1.4.1" | - |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.4.2 Search vendor "Haproxy" for product "Haproxy" and version "1.4.2" | - |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.4.3 Search vendor "Haproxy" for product "Haproxy" and version "1.4.3" | - |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.4.4 Search vendor "Haproxy" for product "Haproxy" and version "1.4.4" | - |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.4.5 Search vendor "Haproxy" for product "Haproxy" and version "1.4.5" | - |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.4.6 Search vendor "Haproxy" for product "Haproxy" and version "1.4.6" | - |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.4.7 Search vendor "Haproxy" for product "Haproxy" and version "1.4.7" | - |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.4.8 Search vendor "Haproxy" for product "Haproxy" and version "1.4.8" | - |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.4.9 Search vendor "Haproxy" for product "Haproxy" and version "1.4.9" | - |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.4.10 Search vendor "Haproxy" for product "Haproxy" and version "1.4.10" | - |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.4.11 Search vendor "Haproxy" for product "Haproxy" and version "1.4.11" | - |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.4.12 Search vendor "Haproxy" for product "Haproxy" and version "1.4.12" | - |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.4.13 Search vendor "Haproxy" for product "Haproxy" and version "1.4.13" | - |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.4.14 Search vendor "Haproxy" for product "Haproxy" and version "1.4.14" | - |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.4.15 Search vendor "Haproxy" for product "Haproxy" and version "1.4.15" | - |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.4.16 Search vendor "Haproxy" for product "Haproxy" and version "1.4.16" | - |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.4.17 Search vendor "Haproxy" for product "Haproxy" and version "1.4.17" | - |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.4.18 Search vendor "Haproxy" for product "Haproxy" and version "1.4.18" | - |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.4.19 Search vendor "Haproxy" for product "Haproxy" and version "1.4.19" | - |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.4.20 Search vendor "Haproxy" for product "Haproxy" and version "1.4.20" | - |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.4.21 Search vendor "Haproxy" for product "Haproxy" and version "1.4.21" | - |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.4.22 Search vendor "Haproxy" for product "Haproxy" and version "1.4.22" | - |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.4.23 Search vendor "Haproxy" for product "Haproxy" and version "1.4.23" | - |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.5 Search vendor "Haproxy" for product "Haproxy" and version "1.5" | dev |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.5 Search vendor "Haproxy" for product "Haproxy" and version "1.5" | dev0 |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.5 Search vendor "Haproxy" for product "Haproxy" and version "1.5" | dev1 |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.5 Search vendor "Haproxy" for product "Haproxy" and version "1.5" | dev10 |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.5 Search vendor "Haproxy" for product "Haproxy" and version "1.5" | dev11 |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.5 Search vendor "Haproxy" for product "Haproxy" and version "1.5" | dev12 |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.5 Search vendor "Haproxy" for product "Haproxy" and version "1.5" | dev13 |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.5 Search vendor "Haproxy" for product "Haproxy" and version "1.5" | dev14 |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.5 Search vendor "Haproxy" for product "Haproxy" and version "1.5" | dev15 |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.5 Search vendor "Haproxy" for product "Haproxy" and version "1.5" | dev16 |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.5 Search vendor "Haproxy" for product "Haproxy" and version "1.5" | dev17 |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.5 Search vendor "Haproxy" for product "Haproxy" and version "1.5" | dev18 |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.5 Search vendor "Haproxy" for product "Haproxy" and version "1.5" | dev2 |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.5 Search vendor "Haproxy" for product "Haproxy" and version "1.5" | dev3 |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.5 Search vendor "Haproxy" for product "Haproxy" and version "1.5" | dev4 |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.5 Search vendor "Haproxy" for product "Haproxy" and version "1.5" | dev5 |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.5 Search vendor "Haproxy" for product "Haproxy" and version "1.5" | dev6 |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.5 Search vendor "Haproxy" for product "Haproxy" and version "1.5" | dev7 |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.5 Search vendor "Haproxy" for product "Haproxy" and version "1.5" | dev8 |
Affected
| ||||||
Haproxy Search vendor "Haproxy" | Haproxy Search vendor "Haproxy" for product "Haproxy" | 1.5 Search vendor "Haproxy" for product "Haproxy" and version "1.5" | dev9 |
Affected
|