CVE-2020-11100: High severity haproxy vulnerability
A flaw was found in the way haproxy processed certain HTTP/2 request packets. An attacker could send crafted HTTP/2 request packets which cause memory corruption, leading to a crash or potential remote arbitrary code execution with the permissions of the user running haproxy.
Other sources
In hpackdhtinsert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.
— Ubuntu
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-11100.
What is the severity of CVE-2020-11100?
The severity of CVE-2020-11100 is high with a severity value of 8.8.
What software versions are affected by CVE-2020-11100?
The versions affected by CVE-2020-11100 include HAProxy 1.8 through 2.x before 2.1.4.
How can a remote attacker exploit CVE-2020-11100?
A remote attacker can exploit CVE-2020-11100 by sending a crafted HTTP/2 request, which can allow them to write arbitrary bytes around a certain location on the heap, possibly leading to remote code execution.
Are there any remediation steps available for CVE-2020-11100?
Yes, there are remediation steps available for CVE-2020-11100. Please refer to the official references for more information on how to mitigate this vulnerability.