Infinite Recursion and Stack Exhaustion Vulnerability in HAProxy

Infinite Recursion and Stack Exhaustion Vulnerability in HAProxy

CVE-2018-20103 · MEDIUM Severity

AV:N/AC:L/AU:N/C:N/I:N/A:P

An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a crafted packet can trigger infinite recursion by making the pointer point to itself, or create a long chain of valid pointers resulting in stack exhaustion.

Learn more about our Web Application Penetration Testing UK.