The haproxy hpack implementation in hpack-tbl.c handles
0-length HTTP headers incorrectly. This can lead to a fully
controlled relative out-of-bounds write when processing a malicious
HTTP2 request (or response).
Pensée du jour :
Ce que l'homme a fait ,
l'homme peut le défaire.
"No secure path in the world"
