Multiple integer overflows in the http_request_forward_body function in proto_http.c in HAProxy 1.5-dev23 before 1.5.4 allow remote attackers to cause a denial of service (crash) via a large stream of data, which triggers a buffer overflow and an out-of-bounds read.
http://www.openwall.com/lists/oss-security/2014/09/09/23
http://secunia.com/advisories/61507
http://secunia.com/advisories/59936