Vulnerability Description
HAProxy before 1.9.7 mishandles a reload with rotated keys, which triggers use of uninitialized, and very predictable, HMAC keys. This is related to an include/types/ssl_sock.h error.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Haproxy | Haproxy | >= 1.9.2, < 1.9.7 |
Related Weaknesses (CWE)
References
- http://git.haproxy.org/?p=haproxy.git%3Ba=commit%3Bh=8ef706502aa2000531d36e4ac56
- https://www.mail-archive.com/haproxy%40formilux.org/msg33410.html
- http://git.haproxy.org/?p=haproxy.git%3Ba=commit%3Bh=8ef706502aa2000531d36e4ac56
- https://www.mail-archive.com/haproxy%40formilux.org/msg33410.html
FAQ
What is CVE-2019-11323?
CVE-2019-11323 is a vulnerability with a CVSS score of 5.9 (MEDIUM). HAProxy before 1.9.7 mishandles a reload with rotated keys, which triggers use of uninitialized, and very predictable, HMAC keys. This is related to an include/types/ssl_sock.h error.
How severe is CVE-2019-11323?
CVE-2019-11323 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-11323?
Check the references section above for vendor advisories and patch information. Affected products include: Haproxy Haproxy.