CVE-2019-11323

HAProxy before 1.9.7 mishandles a reload with rotated keys, which triggers use of uninitialized, and very predictable, HMAC keys. This is related to an include/types/ssl_sock.h error.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:haproxy:haproxy:*:*:*:*:*:*:*:*

Information

Published : 2019-05-09 07:29

Updated : 2021-07-21 04:39


NVD link : CVE-2019-11323

Mitre link : CVE-2019-11323


JSON object : View

CWE
CWE-908

Use of Uninitialized Resource

CWE-327

Use of a Broken or Risky Cryptographic Algorithm

Advertisement

dedicated server usa

Products Affected

haproxy

  • haproxy