PT-2014-5477 · Hapi · Hapi
Publicado
2014-05-16
·
Atualizado
2017-10-24
·
CVE-2014-3742
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
hapi server framework versions 2.0.x through 2.1.x
Description
The issue allows remote attackers to cause a denial of service via unspecified vectors, resulting in file descriptor consumption and process crash. This is due to a file descriptor leak that, when triggered repeatedly, will cause the server to run out of file descriptors and the node process to die. The effort required to take down a server depends on the process file descriptor limit.
Recommendations
For versions 2.0.x and 2.1.x, please upgrade to version 2.2.x or above as soon as possible.
Correção
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Hapi