CVE-2019-19330 - Debian Debian Linux, Haproxy Haproxy and Canonical Ubuntu Linux

Critical 9.8

The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.

Affected software

Debian Debian Linux

Haproxy Haproxy

Canonical Ubuntu Linux

Reference links

Get alerted to vulnerabilities in your software

CVE alerts, vulnerability alerts, latest versions and news matched to your software stack.