Felix Wilhelm of Google Project Zero discovered that HAProxy, a TCP/HTTP
reverse proxy, did not properly handle HTTP/2 headers. This would allow
an attacker to write arbitrary bytes around a certain location on the
heap, resulting in denial-of-service or potential arbitrary code
execution.
Intelligence View
⚡ tsecurity.de Intelligence
DSA-4649 haproxy - security update
Felix Wilhelm of Google Project Zero discovered that HAProxy, a TCP/HTTP reverse proxy, did not properly handle HTTP/2 headers. This would allow an attacker to…