PT-2014-5477 · Hapi · Hapi

Publicado

2014-05-16

·

Atualizado

2017-10-24

·

CVE-2014-3742

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions hapi server framework versions 2.0.x through 2.1.x
Description The issue allows remote attackers to cause a denial of service via unspecified vectors, resulting in file descriptor consumption and process crash. This is due to a file descriptor leak that, when triggered repeatedly, will cause the server to run out of file descriptors and the node process to die. The effort required to take down a server depends on the process file descriptor limit.
Recommendations For versions 2.0.x and 2.1.x, please upgrade to version 2.2.x or above as soon as possible.

Correção

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-3742
GHSA-CQR7-78PJ-3G7J

Produtos afetados

Hapi