Amazon Linux 2 Security Advisory: ALASHAPROXY2-2023-001
Advisory Release Date: 2023-08-04 20:34 Pacific
Advisory Updated Date: 2023-09-25 22:11 Pacific
A flaw was found in the way HAProxy processed HTTP responses containing the Set-Cookie2 header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability. (CVE-2022-0711)
Affected Packages:
haproxy2
Note:
This advisory is applicable to Amazon Linux 2 - Haproxy2 Extra. Visit this page to learn more about Amazon Linux 2 (AL2) Extras and this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update haproxy2 to update your system.
aarch64:
haproxy2-2.2.17-1.amzn2.0.2.aarch64
haproxy2-debuginfo-2.2.17-1.amzn2.0.2.aarch64
src:
haproxy2-2.2.17-1.amzn2.0.2.src
x86_64:
haproxy2-2.2.17-1.amzn2.0.2.x86_64
haproxy2-debuginfo-2.2.17-1.amzn2.0.2.x86_64