Bugzilla – Bug 1142529
VUL-1: CVE-2019-14241: haproxy: cookie memory corruption
Last modified: 2021-04-19 09:25:50 UTC
only openSUSE Factory has something newer than 1.8.x
Updating openSUSE:Factory to 2.0.3 or higher will fix this. No other releases are affected.
Public through https://github.com/haproxy/haproxy/issues/181
Both issues mentioned in the github issue are resolved by this submission: https://build.opensuse.org/request/show/719848
SUSE-SU-2019:3001-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1142529 CVE References: CVE-2019-14241 Sources used: SUSE Linux Enterprise High Availability 15-SP1 (src): haproxy-2.0.5+git0.d905f49a-8.3.5 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2019:3002-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1142529 CVE References: CVE-2019-14241 Sources used: SUSE Linux Enterprise High Availability 15 (src): haproxy-2.0.5+git0.d905f49a-3.12.6 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2019:2555-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1142529 CVE References: CVE-2019-14241 Sources used: openSUSE Leap 15.0 (src): haproxy-2.0.5+git0.d905f49a-lp150.2.13.1
openSUSE-SU-2019:2556-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1142529 CVE References: CVE-2019-14241 Sources used: openSUSE Leap 15.1 (src): haproxy-2.0.5+git0.d905f49a-lp151.2.3.1