{"id":"CLSA-2024-1733908866","summary":"Fix CVE(s): CVE-2023-25725","details":"   * SECURITY UPDATE: The HTTP header parsers in HAProxy may accept empty\n     header field names\n     - debian/patches/CVE-2023-25725.patch: prevent empty header field\n       names\n     - CVE-2023-25725","modified":"2026-06-04T09:46:40.477153753Z","published":"2024-12-11T09:21:12Z","upstream":["CVE-2023-25725"],"references":[{"type":"ADVISORY","url":"https://errata.cloudlinux.com/ubuntu16-els/CLSA-2024-1733908866.html"}],"affected":[{"package":{"name":"haproxy","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/haproxy?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.3-1ubuntu0.3+tuxcare.els2"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2024-1733908866.json"}},{"package":{"name":"haproxy-doc","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/haproxy-doc?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.3-1ubuntu0.3+tuxcare.els2"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2024-1733908866.json"}},{"package":{"name":"vim-haproxy","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/vim-haproxy?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.3-1ubuntu0.3+tuxcare.els2"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2024-1733908866.json"}}],"schema_version":"1.7.5"}