~ubuntu-branches/ubuntu/precise/haproxy/precise-security

Viewing all changes in revision 16.

  • Committer: Package Import Robot
  • Author(s): Marc Deslauriers
  • Date: 2013-04-05 10:21:10 UTC
  • Revision ID: package-import@ubuntu.com-20130405102110-mw5yhizd0oeeskwz
Tags: 1.4.18-0ubuntu1.1
* SECURITY UPDATE: denial of service and possible arbitrary code
  execution via non-default global.tune.bufsize.
  - debian/patches/CVE-2012-2942.patch: check buffer sizes in
    include/types/global.h, src/acl.c, src/cfgparse.c, src/checks.c,
    src/dumpstats.c, src/haproxy.c, src/proto_http.c,
    tests/0000-debug-stats.diff.
  - CVE-2012-2942
* SECURITY UPDATE: denial of service via HTTP information in tcp-request
  - debian/patches/CVE-2013-1912.patch: properly handle buffers in
    src/proto_http.c.
  - CVE-2013-1912

expand all expand all

Show diffs side-by-side

added added

removed removed

Lines of Context: