CVE-2019-19330

NameCVE-2019-19330
DescriptionThe HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-4577-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
haproxy (PTS)jessie1.5.8-3+deb8u2fixed
jessie (security)1.5.8-3+deb8u1fixed
stretch1.7.5-2fixed
buster1.8.19-1vulnerable
buster (security)1.8.19-1+deb10u1fixed
bullseye, sid2.0.10-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
haproxysource(unstable)2.0.10-1
haproxysourcebuster1.8.19-1+deb10u1DSA-4577-1
haproxysourcejessie(not affected)
haproxysourcestretch(not affected)

Notes

[stretch] - haproxy <not-affected> (Vulnerable code introduced in 1.8)
[jessie] - haproxy <not-affected> (Vulnerable code introduced in 1.8)
https://git.haproxy.org/?p=haproxy.git;a=commit;h=54f53ef7ce4102be596130b44c768d1818570344
https://git.haproxy.org/?p=haproxy.git;a=commit;h=146f53ae7e97dbfe496d0445c2802dd0a30b0878

Search for package or bug name: Reporting problems