CVE-2016-5360

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

HAproxy 1.6.x before 1.6.6, when a deny comes from a reqdeny rule, allows remote attackers to cause a denial of service (uninitialized memory access and crash) or possibly have unspecified other impact via unknown vectors.

References

http://git.haproxy.org/?p=haproxy-1.6.git;a=commit;h=60f01f8c89e4fb2723d5a9f2046286e699567e0b

http://www.openwall.com/lists/oss-security/2016/06/09/5

http://www.openwall.com/lists/oss-security/2016/06/09/6

http://www.ubuntu.com/usn/USN-3011-1

Details

Source: MITRE

Published: 2016-06-30

Updated: 2016-07-01

Type: CWE-119

Risk Information

CVSS v2

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Impact Score: 3.6

Exploitability Score: 3.9

Severity: HIGH

Tenable Plugins

View all (5 total)

IDNameProductFamilySeverity
121649Photon OS 1.0: Haproxy PHSA-2016-0012NessusPhotonOS Local Security Checks
critical
111846Photon OS 1.0: Dnsmasq / Grub2 / Haproxy / Linux / Nginx / Vim / Wget / Zookeeper PHSA-2016-0012 (deprecated)NessusPhotonOS Local Security Checks
critical
92284Fedora 24 : haproxy (2016-b38938aa8e)NessusFedora Local Security Checks
high
91912FreeBSD : haproxy -- denial of service (f1c219ba-3f14-11e6-b3c8-14dae9d210b8)NessusFreeBSD Local Security Checks
high
91727Ubuntu 16.04 LTS : haproxy vulnerability (USN-3011-1)NessusUbuntu Local Security Checks
high