PT-2023-29548 · Daurnimator+1 · Lua-Http+1

Artur Łącki

+1

·

Publicado

2023-09-05

·

Atualizado

2024-10-10

·

CVE-2023-4540

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions lua-http versions before commit ddab283
Description The issue is related to an Improper Handling of Exceptional Conditions vulnerability in the Daurnimator lua-http library, which allows Excessive Allocation and a denial of service (DoS) attack to be executed by sending a properly crafted request to the server. Such a request causes the program to enter an infinite loop.
Recommendations For lua-http versions before commit ddab283, update to a version after commit ddab283 to resolve the issue. As a temporary workaround, consider restricting access to the lua-http library to minimize the risk of exploitation. Avoid using the library until the issue is resolved.

Correção

DoS

Improper Handling of Exceptional Conditions

Infinite Loop

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-4540

Produtos afetados

Debian
Lua-Http