HAProxy Security Update (CVE-2023-25725)mail-archive.com 40 pointspeanball3 years ago6 commentsSaveHideCopy link On HNComments−nvahalik3yCVE-2023-25725 on Debian: https://security-tracker.debian.org/tracker/CVE-2023-25725It's fixed in 2.2.9-2+deb11u4.−wtarreau3yJust to clarify some doubts, distro packages issued yesterday all have the fix in them even if the base version number appears older.−theandrewbailey3y Branch Vulnerable Fixed Maintained until ---------+------------------------+----------+----------------- ... 2.4 2.4.0 .. 2.4.21 2.4.12 2026-Q2 (LTS) So 2.4 was fixed a long time ago? I just did an update and got 2.4.21, so I'm still vulnerable!−max-m3yI think this was a typo in the table. 2.4.22 was released alongside the other fixed versions.−wtarreau3yconfirmed, thanks for correcting me. Dealing with such reports across many versions and copy-pasting lots of data & Git commit IDs is extremely prone to failures, even after careful re-reading.−exabrial3yplease tell me this won't be part of phased updates
Comments
CVE-2023-25725 on Debian: https://security-tracker.debian.org/tracker/CVE-2023-25725
It's fixed in 2.2.9-2+deb11u4.
Just to clarify some doubts, distro packages issued yesterday all have the fix in them even if the base version number appears older.
I think this was a typo in the table. 2.4.22 was released alongside the other fixed versions.
confirmed, thanks for correcting me. Dealing with such reports across many versions and copy-pasting lots of data & Git commit IDs is extremely prone to failures, even after careful re-reading.
please tell me this won't be part of phased updates