-
Committer:
Package Import Robot
-
Author(s):
Marc Deslauriers
-
Date:
2013-04-05 10:22:37 UTC
-
Revision ID:
package-import@ubuntu.com-20130405102237-v1nup4tk27ardkck
Tags: 1.4.15-1ubuntu0.1
* SECURITY UPDATE: denial of service and possible arbitrary code
execution via non-default global.tune.bufsize.
- debian/patches/CVE-2012-2942.patch: check buffer sizes in
include/types/global.h, src/acl.c, src/cfgparse.c, src/checks.c,
src/dumpstats.c, src/haproxy.c, src/proto_http.c,
tests/0000-debug-stats.diff.
- CVE-2012-2942
* SECURITY UPDATE: denial of service via HTTP information in tcp-request
- debian/patches/CVE-2013-1912.patch: properly handle buffers in
src/proto_http.c.
- CVE-2013-1912