SUSE-SU-2015:1776-1

    Dashboard / Vulnerabilities / SUSE-SU-2015:1776-1

    SUSE-SU-2015:1776-1

    Published: 25 Sept 2015Last Modified: 4 Feb 2026
    Upstream:
    Aliases:

    Summary: Security update for haproxy

    Details: haxproy was updated to backport various security fixes and related patches (bsc#937202) (bsc#937042) (CVE-2015-3281) + BUG/MAJOR: buffers: make the buffer_slow_realign() function respect output data + BUG/MINOR: ssl: fix smp_fetch_ssl_fc_session_id + MEDIUM: ssl: replace standards DH groups with custom ones + BUG/MEDIUM: ssl: fix tune.ssl.default-dh-param value being overwritten + MINOR: ssl: add a destructor to free allocated SSL ressources + BUG/MINOR: ssl: Display correct filename in error message + MINOR: ssl: load certificates in alphabetical order + BUG/MEDIUM: checks: fix conflicts between agent checks and ssl healthchecks + BUG/MEDIUM: ssl: force a full GC in case of memory shortage + BUG/MEDIUM: ssl: fix bad ssl context init can cause segfault in case of OOM. + BUG/MINOR: ssl: correctly initialize ssl ctx for invalid certificates + MINOR: ssl: add statement to force some ssl options in global. + MINOR: ssl: add fetchs 'ssl_c_der' and 'ssl_f_der' to return DER formatted certs Also the init script was fixed for the haproxy status checks (bsc#947204)

    Affected packages

    Package

    Name: haproxy

    Purl: pkg:rpm/suse/haproxy&distro=SUSE%20OpenStack%20Cloud%205

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.5.4-12.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High