Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.854151
Category:SuSE Local Security Checks
Title:openSUSE: Security Advisory for haproxy (openSUSE-SU-2021:2975-1)
Summary:The remote host is missing an update for the 'haproxy'; package(s) announced via the openSUSE-SU-2021:2975-1 advisory.
Description:Summary:
The remote host is missing an update for the 'haproxy'
package(s) announced via the openSUSE-SU-2021:2975-1 advisory.

Vulnerability Insight:
This update for haproxy fixes the following issues:

- CVE-2021-40346: Fixed request smuggling vulnerability in HTX
(bsc#1189877).

Affected Software/OS:
'haproxy' package(s) on openSUSE Leap 15.3.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2021-40346
Debian Security Information: DSA-4968 (Google Search)
https://www.debian.org/security/2021/dsa-4968
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/A7V2IYO22LWVBGUNZWVKNTMDV4KINLFO/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MXTSBY2TEAXWZVFQM3CXHJFRONX7PEMN/
https://git.haproxy.org/?p=haproxy.git
https://github.com/haproxy/haproxy/commit/3b69886f7dcc3cfb3d166309018e6cfec9ce2c95
https://jfrog.com/blog/critical-vulnerability-in-haproxy-cve-2021-40346-integer-overflow-enables-http-smuggling/
https://www.mail-archive.com/haproxy@formilux.org
https://www.mail-archive.com/haproxy@formilux.org/msg41114.html
https://lists.apache.org/thread.html/r284567dd7523f5823e2ce995f787ccd37b1cc4108779c50a97c79120@%3Cdev.cloudstack.apache.org%3E
https://lists.apache.org/thread.html/r8a58fd7a29808e5d27ee56877745e58dc4bb041b9af94601554e2a5a@%3Cdev.cloudstack.apache.org%3E
CopyrightCopyright (C) 2021 Greenbone Networks GmbH

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.