Your message dated Fri, 29 Dec 2023 12:17:08 +0000
with message-id <[email protected]>
and subject line Bug#1043502: fixed in haproxy 2.6.12-1+deb12u1
has caused the Debian Bug report #1043502,
regarding haproxy: CVE-2023-40225
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1043502: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1043502
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: haproxy
Version: 2.6.14-1
Severity: important
Tags: security upstream
Forwarded: https://github.com/haproxy/haproxy/issues/2237
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for haproxy.
CVE-2023-40225[0]:
| HAProxy through 2.0.32, 2.1.x and 2.2.x through 2.2.30, 2.3.x and
| 2.4.x through 2.4.23, 2.5.x and 2.6.x before 2.6.15, 2.7.x before
| 2.7.10, and 2.8.x before 2.8.2 forwards empty Content-Length
| headers, violating RFC 9110 section 8.6. In uncommon cases, an
| HTTP/1 server behind HAProxy may interpret the payload as an extra
| request.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2023-40225
https://www.cve.org/CVERecord?id=CVE-2023-40225
[1] https://github.com/haproxy/haproxy/issues/2237
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: haproxy
Source-Version: 2.6.12-1+deb12u1
Done: Salvatore Bonaccorso <[email protected]>
We believe that the bug you reported is fixed in the latest version of
haproxy, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Salvatore Bonaccorso <[email protected]> (supplier of updated haproxy package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sat, 16 Dec 2023 17:41:30 +0100
Source: haproxy
Architecture: source
Version: 2.6.12-1+deb12u1
Distribution: bookworm-security
Urgency: high
Maintainer: Debian HAProxy Maintainers <[email protected]>
Changed-By: Salvatore Bonaccorso <[email protected]>
Closes: 1043502
Changes:
haproxy (2.6.12-1+deb12u1) bookworm-security; urgency=high
.
* Non-maintainer upload by the Security Team.
* REORG: http: move has_forbidden_char() from h2.c to http.h
* BUG/MAJOR: h3: reject header values containing invalid chars
* BUG/MAJOR: http: reject any empty content-length header value
(CVE-2023-40225) (Closes: #1043502)
* MINOR: ist: add new function ist_find_range() to find a character range
* MINOR: http: add new function http_path_has_forbidden_char()
* MINOR: h2: pass accept-invalid-http-request down the request parser
* REGTESTS: http-rules: add accept-invalid-http-request for normalize-uri
tests
* BUG/MINOR: h1: do not accept '#' as part of the URI component
(CVE-2023-45539)
* BUG/MINOR: h2: reject more chars from the :path pseudo header
* BUG/MINOR: h3: reject more chars from the :path pseudo header
* REGTESTS: http-rules: verify that we block '#' by default for
normalize-uri
* DOC: clarify the handling of URL fragments in requests
Checksums-Sha1:
48d9e71d3278b144ae485eb55dd29ec3d889833a 2529 haproxy_2.6.12-1+deb12u1.dsc
d12745cff8fbcdd82d4d6fe1fc679d3bdb871c4c 4060878 haproxy_2.6.12.orig.tar.gz
95a59df2801d33e55678cb0a6635008d291d9d0c 85884
haproxy_2.6.12-1+deb12u1.debian.tar.xz
323a9fe921f16d0cd513c54b6c6f0ff8ae35f823 7281
haproxy_2.6.12-1+deb12u1_source.buildinfo
Checksums-Sha256:
96b43083226a0c2c79f4fb869efb5d829e44726b58ec99fde3f8b09eb88ea726 2529
haproxy_2.6.12-1+deb12u1.dsc
58f9edb26bf3288f4b502658399281cc5d6478468bd178eafe579c8f41895854 4060878
haproxy_2.6.12.orig.tar.gz
8d0f3ab86c34728e8cb7c331d659453949d8dd143d9dd7dbe63a1d54cd164a5b 85884
haproxy_2.6.12-1+deb12u1.debian.tar.xz
bd5d37f28f5f1b5fd3e45bbeaa963c6854f2bd96ff120dc2920675b1db0a9c9e 7281
haproxy_2.6.12-1+deb12u1_source.buildinfo
Files:
9818de16eee29247f778297e461b67e4 2529 net optional haproxy_2.6.12-1+deb12u1.dsc
215f5c315e5881f19b974c1d48581098 4060878 net optional
haproxy_2.6.12.orig.tar.gz
b2e415d63ed06458635a09edfbccb8aa 85884 net optional
haproxy_2.6.12-1+deb12u1.debian.tar.xz
aafc98dbc5fbe52c67e56033d0c7d7e1 7281 net optional
haproxy_2.6.12-1+deb12u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmWGjbBfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89EcYoP+wfEXSgqobEgEgAw3P3ZbfRsmp+m+iXD
tEzcfmk0HQi2ggKa5ZNtw2goF9oUevfbPg9KOQ+rKaSTftpe6IfESGm1lSyfQAZn
pqgDm6yk2CJR3conwRdyGfYltzjn3HndxUqVQfCRVxC7ZLwvH1Qjp6mJcUbUJGzM
G38KbzLBAdIqJYKq+V1XQvaOL5zE1n8nTo0KTJwDJ62oNPIygKa/QPU6eGgMjTvu
TYU2DPD7oROlQ4hYIOmk22xcDRafDPYkE3axEC7SUfl575YQaLIXLnhbALp+2lSv
+j66KNwwFCttV08SJP44jnukc/CaXu8Y+7kATu0gx9uZgIHveXTiuSmKV7MonKsk
fxkU9V1UY29agTAIkuk/LVSDHkBXdmGCdNj4sBgRXDufj4K/Z65KYeS+3ET/gN7v
P/5zheo7hMPu4wh/viq5/UhPzxRKSUTtyIet2a+/29jJGnHweJT4yPpHwPSCPgnt
Yxjmgo9wyj1xExUOvIGrC+bz/CxwQo3V2lrP/LWBQ3PTll32kRz5OR9wrflmwnDp
RuKtGIvDaL5F/UnAz41vVTPpXnmPwA87P+uamIzLhPi+VycZzLHPJl2lMPnw39VY
a38wJKbU1/FfLVjFYxdYG7/Bt9zBcjF0Th/gZ0O7U0vJS6aBWYDU/hpc6DG29Pyk
EWu0dXFAoPgP
=eVWj
-----END PGP SIGNATURE-----
--- End Message ---