Your message dated Fri, 29 Dec 2023 12:17:37 +0000
with message-id <[email protected]>
and subject line Bug#1043502: fixed in haproxy 2.2.9-2+deb11u6
has caused the Debian Bug report #1043502,
regarding haproxy: CVE-2023-40225
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1043502: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1043502
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: haproxy
Version: 2.6.14-1
Severity: important
Tags: security upstream
Forwarded: https://github.com/haproxy/haproxy/issues/2237
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for haproxy.
CVE-2023-40225[0]:
| HAProxy through 2.0.32, 2.1.x and 2.2.x through 2.2.30, 2.3.x and
| 2.4.x through 2.4.23, 2.5.x and 2.6.x before 2.6.15, 2.7.x before
| 2.7.10, and 2.8.x before 2.8.2 forwards empty Content-Length
| headers, violating RFC 9110 section 8.6. In uncommon cases, an
| HTTP/1 server behind HAProxy may interpret the payload as an extra
| request.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2023-40225
https://www.cve.org/CVERecord?id=CVE-2023-40225
[1] https://github.com/haproxy/haproxy/issues/2237
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: haproxy
Source-Version: 2.2.9-2+deb11u6
Done: Salvatore Bonaccorso <[email protected]>
We believe that the bug you reported is fixed in the latest version of
haproxy, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Salvatore Bonaccorso <[email protected]> (supplier of updated haproxy package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sat, 23 Dec 2023 11:02:19 +0100
Source: haproxy
Architecture: source
Version: 2.2.9-2+deb11u6
Distribution: bullseye-security
Urgency: high
Maintainer: Debian HAProxy Maintainers <[email protected]>
Changed-By: Salvatore Bonaccorso <[email protected]>
Closes: 1043502
Changes:
haproxy (2.2.9-2+deb11u6) bullseye-security; urgency=high
.
* Non-maintainer upload by the Security Team.
* BUG/MAJOR: http: reject any empty content-length header value
(CVE-2023-40225) (Closes: #1043502)
* MINOR: ist: add new function ist_find_range() to find a character range
* MINOR: ist: Add istend() function to return a pointer to the end of the
string
* MINOR: http: add new function http_path_has_forbidden_char()
* MINOR: h2: pass accept-invalid-http-request down the request parser
* BUG/MINOR: h1: do not accept '#' as part of the URI component
(CVE-2023-45539)
* BUG/MINOR: h2: reject more chars from the :path pseudo header
* REGTESTS: http-rules: verify that we block '#' by default for
normalize-uri
* DOC: clarify the handling of URL fragments in requests
Checksums-Sha1:
0becf203cd3be52e38f35abe8e89f43399de90ed 2470 haproxy_2.2.9-2+deb11u6.dsc
56d96d3a710415484695cd548300a49bd73fcdb9 93076
haproxy_2.2.9-2+deb11u6.debian.tar.xz
624fef302bc838ceff0d5f1530db60c9b2524868 7277
haproxy_2.2.9-2+deb11u6_source.buildinfo
Checksums-Sha256:
b6d7d470a115efee6bfa6b7feb741883f4febba8035d25a2e0aa6a81caae7a05 2470
haproxy_2.2.9-2+deb11u6.dsc
347cacfaa24b7de2165d8bfe15fa15dd6ab6bce4d45b075a63b019b181dc239b 93076
haproxy_2.2.9-2+deb11u6.debian.tar.xz
83234d8d92a3e78b79f8da965e4ad3173ddcc4c5c318a2ad7e3ae6dbd90370a3 7277
haproxy_2.2.9-2+deb11u6_source.buildinfo
Files:
c732ec27fa9736496eb16e6af5cfcbb4 2470 net optional haproxy_2.2.9-2+deb11u6.dsc
47bdae4716038484ba3e501c201c5940 93076 net optional
haproxy_2.2.9-2+deb11u6.debian.tar.xz
d1f502e5fc920f7d09cb96b3d9bd3ffd 7277 net optional
haproxy_2.2.9-2+deb11u6_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQKlBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmWNUTlfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89EPbAP9RfYE4+gBXEgRanaR86Ulg6ALsgRnLG+
P/XgtuMuAC96kSx55mNzp+CKUBI0t2k6/5qj0cQeen01cuiKWr+YyvJVjPN1ycmw
z2Eq/+rrvGkLipJwVMGBIweEVbYM3ULLsok3MShTGd2UrPoKSPrUmDzO5oHTVeso
D7cbPxfL9nmsVjun3tFZZOnDvhwtETw/JRG8mIKa5ZpXqpTnQpoPecr/sQkswi/g
p5tdCYyAwY8ZsQT4xixPFd7FZGTjQta0k4vtrqTuE/2xUSGfHDm3usulXjHcS9kL
Cqfz1I/Teky5PZ3IPUOt64B/d7j2AyQ20l9p5ypzL7LCpbqH5S9q7M1Zvo1A407P
EGHcRClHq50GnhodJAv8DKwIpL6he0fBZaC/DWy3P3A6i1h1xTXXtk3sjaN4EHHI
L/CjCP+SQIy0PM0J42bC0EJt+55nqrI+3i3bbRPfjZsa3/6Kl6zvJ2txhM22Xo8w
nj8xStjacepSAS9bmdDzcbJyGGuUTmJYBwraDRiNYI2WMLGUVrTcrjEtazxyKloK
3wD9Bp9/VsVgMl7LqrG00PzHF2LYo31Efh4MebRxmufZcI99NBN2JBEpWNmHioT7
1H5Yx2G6rk0qHAjO0HFuYEfFzs1TIMWI4HHd+0balI5SGOUssBR6W5vaU//Qq7V0
XIIa6JunLrQ=
=rY71
-----END PGP SIGNATURE-----
--- End Message ---