Re: Revisiting CVE-2023-45539

2024-03-13 Thread Willy Tarreau
Hi Ryan, On Mon, Mar 04, 2024 at 12:13:48PM -0600, Ryan O'Hara wrote: > I am looking at CVE-2023-45539 as it affects older versions of haproxy (ie. > haproxy-1.8). At this point I have verified that 1.8 is affected by this > issue, which is in agreement with the original bug/commit which states >

Revisiting CVE-2023-45539

2024-03-04 Thread Ryan O'Hara
I am looking at CVE-2023-45539 as it affects older versions of haproxy (ie. haproxy-1.8). At this point I have verified that 1.8 is affected by this issue, which is in agreement with the original bug/commit which states versions prior to 2.8 need a backport. I am wondering if anyone has attempted