Improper Handling of Exceptional Conditions vulnerability in Daurnimator lua-http library allows Excessive Allocation and a denial of service (DoS) attack to be executed by sending a properly crafted request to the server.
Such a request causes the program to enter an infinite loop.

This issue affects lua-http: all versions before commit ddab283.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-54395 Improper Handling of Exceptional Conditions vulnerability in Daurnimator lua-http library allows Excessive Allocation and a denial of service (DoS) attack to be executed by sending a properly crafted request to the server. Such a request causes the program to enter an infinite loop. This issue affects lua-http: all versions before commit ddab283.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 14 Mar 2025 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-835

Fri, 22 Nov 2024 12:00:00 +0000

Type Values Removed Values Added
References

Thu, 10 Oct 2024 16:30:00 +0000

Type Values Removed Values Added
References

Thu, 10 Oct 2024 15:45:00 +0000

Type Values Removed Values Added
Description Improper Handling of Exceptional Conditions vulnerability in Daurnimator lua-http library allows Excessive Allocation and a denial of service (DoS) attack to be executed by sending a properly crafted request to the server. This issue affects lua-http: all versions before commit ddab283. Improper Handling of Exceptional Conditions vulnerability in Daurnimator lua-http library allows Excessive Allocation and a denial of service (DoS) attack to be executed by sending a properly crafted request to the server. Such a request causes the program to enter an infinite loop. This issue affects lua-http: all versions before commit ddab283.
Weaknesses CWE-835
References

Mon, 30 Sep 2024 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2025-04-04T18:33:32.557Z

Reserved: 2023-08-25T11:34:40.887Z

Link: CVE-2023-4540

cve-icon Vulnrichment

Updated: 2024-08-02T07:31:06.067Z

cve-icon NVD

Status : Modified

Published: 2023-09-05T08:15:40.017

Modified: 2025-04-04T19:15:45.653

Link: CVE-2023-4540

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.