Fedora 40: haproxy 2024-39913e097a Security Advisory Updates
Summary
HAProxy is a TCP/HTTP reverse proxy which is particularly suited for high
availability environments. Indeed, it can:
- route HTTP requests depending on statically assigned cookies
- spread load among several servers while assuring server persistence
through the use of HTTP cookies
- switch to backup servers in the event a main one fails
- accept connections to special ports dedicated to service monitoring
- stop accepting connections without breaking existing ones
- add, modify, and delete HTTP headers in both directions
- block requests matching particular patterns
- report detailed status to authenticated users from a URI
intercepted from the application
Update Information:
Update to 2.9.10 (CVE-2024-45506)
Change Log
* Wed Sep 4 2024 Ryan O'Hara
References
[ 1 ] Bug #2309744 - CVE-2024-45506 haproxy: potential infinite loop condition in the h2_send() may trigger a DoS [fedora-40]
https://bugzilla.redhat.com/show_bug.cgi?id=2309744
Update Instructions
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-39913e097a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label