PT-2023-29548 · Daurnimator+1 · Lua-Http+1

·

CVE-2023-4540

·

Published

2023-09-05

·

Updated

2024-10-10

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions lua-http versions before commit ddab283
Description The issue is related to an Improper Handling of Exceptional Conditions vulnerability in the Daurnimator lua-http library, which allows Excessive Allocation and a denial of service (DoS) attack to be executed by sending a properly crafted request to the server. Such a request causes the program to enter an infinite loop.
Recommendations For lua-http versions before commit ddab283, update to a version after commit ddab283 to resolve the issue. As a temporary workaround, consider restricting access to the lua-http library to minimize the risk of exploitation. Avoid using the library until the issue is resolved.

Exploit

Fix

DoS

Infinite Loop

Improper Handling of Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-4540

Affected Products

Debian
Lua-Http