PT-2023-29548 · Daurnimator+1 · Lua-Http+1

Artur Łącki

+1

·

Published

2023-09-05

·

Updated

2024-10-10

·

CVE-2023-4540

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions lua-http versions before commit ddab283
Description The issue is related to an Improper Handling of Exceptional Conditions vulnerability in the Daurnimator lua-http library, which allows Excessive Allocation and a denial of service (DoS) attack to be executed by sending a properly crafted request to the server. Such a request causes the program to enter an infinite loop.
Recommendations For lua-http versions before commit ddab283, update to a version after commit ddab283 to resolve the issue. As a temporary workaround, consider restricting access to the lua-http library to minimize the risk of exploitation. Avoid using the library until the issue is resolved.

Fix

DoS

Improper Handling of Exceptional Conditions

Infinite Loop

Weakness Enumeration

Related Identifiers

CVE-2023-4540

Affected Products

Debian
Lua-Http