ALAS-2025-791


Amazon Linux 2023 Security Advisory: ALAS-2025-791
Advisory Release Date: 2025-01-06 19:21 Pacific
Advisory Updated Date: 2025-01-09 13:05 Pacific
Severity: Medium

Issue Overview:

Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy. If this vulnerability is exploited, a remote attacker may access a path that is restricted by ACL (Access Control List) set on the product. As a result, the attacker may obtain sensitive information. (CVE-2024-53008)


Affected Packages:

haproxy


Issue Correction:
Run dnf update haproxy --releasever 2023.6.20250107 to update your system.

New Packages:
aarch64:
    haproxy-debuginfo-2.8.3-1.amzn2023.0.1.aarch64
    haproxy-2.8.3-1.amzn2023.0.1.aarch64
    haproxy-debugsource-2.8.3-1.amzn2023.0.1.aarch64

src:
    haproxy-2.8.3-1.amzn2023.0.1.src

x86_64:
    haproxy-debuginfo-2.8.3-1.amzn2023.0.1.x86_64
    haproxy-2.8.3-1.amzn2023.0.1.x86_64
    haproxy-debugsource-2.8.3-1.amzn2023.0.1.x86_64