CVE-2013-1912 describes a buffer overflow vulnerability in HAProxy versions 1.4 through 1.4.22 and 1.5-dev through 1.5-dev17. This flaw occurs when HTTP keep-alive is enabled, HTTP keywords are used in TCP inspection rules, and rewrite rules append to requests. Remote attackers can exploit this by sending crafted pipelined HTTP requests, leading to a denial of service (crash) and potentially arbitrary code execution. The vulnerability has a CVSS score of 5.1 (medium severity), indicating a network-based attack with high attack complexity, requiring no authentication, and potentially impacting confidentiality, integrity, and availability. Its EPSS score is very low, suggesting a minimal likelihood of exploitation in the wild. There is no evidence of active exploitation, nor are there any public exploit modules available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also extremely low, indicating a lack of widespread attention or concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4CPE matchmatch criteria | cpe:2.3:a:haproxy:haproxy:1.4:*:*:*:*:*:*:* | ||
1.4.20CPE matchmatch criteria | cpe:2.3:a:haproxy:haproxy:1.4.20:*:*:*:*:*:*:* | ||
1.4.22CPE matchmatch criteria | cpe:2.3:a:haproxy:haproxy:1.4.22:*:*:*:*:*:*:* | ||
1.5CPE matchmatch criteria | cpe:2.3:a:haproxy:haproxy:1.5:dev:*:*:*:*:*:* | ||
1.5CPE matchmatch criteria | cpe:2.3:a:haproxy:haproxy:1.5:dev17:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.