PT-2023-29548 · Daurnimator+1 · Lua-Http+1
Artur Łącki
+1
·
Publicado
2023-09-05
·
Atualizado
2024-10-10
·
CVE-2023-4540
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
lua-http versions before commit ddab283
Description
The issue is related to an Improper Handling of Exceptional Conditions vulnerability in the Daurnimator lua-http library, which allows Excessive Allocation and a denial of service (DoS) attack to be executed by sending a properly crafted request to the server. Such a request causes the program to enter an infinite loop.
Recommendations
For lua-http versions before commit ddab283, update to a version after commit ddab283 to resolve the issue. As a temporary workaround, consider restricting access to the lua-http library to minimize the risk of exploitation. Avoid using the library until the issue is resolved.
Correção
DoS
Improper Handling of Exceptional Conditions
Infinite Loop
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Debian
Lua-Http