loona is an experimental, HTTP/1.1 and HTTP/2 implementation in Rust on top of io-uring. `loona-hpack` suffers from the same vulnerability as the original `hpack` as documented in issue #11. All users who try to decode untrusted input using the Decoder are vulnerable to this exploit. This issue has been addressed in release version 0.4.3. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Metrics
Affected Vendors & Products
References
History
Tue, 05 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Mon, 04 Nov 2024 23:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | loona is an experimental, HTTP/1.1 and HTTP/2 implementation in Rust on top of io-uring. `loona-hpack` suffers from the same vulnerability as the original `hpack` as documented in issue #11. All users who try to decode untrusted input using the Decoder are vulnerable to this exploit. This issue has been addressed in release version 0.4.3. All users are advised to upgrade. There are no known workarounds for this vulnerability. | |
Title | Panic Vulnerability in loona-hpack | |
Weaknesses | CWE-755 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-11-04T22:42:29.920Z
Updated: 2024-11-05T16:34:49.562Z
Reserved: 2024-10-28T14:20:59.339Z
Link: CVE-2024-51502
Vulnrichment
Updated: 2024-11-05T16:34:06.311Z
NVD
Status : Awaiting Analysis
Published: 2024-11-04T23:15:05.070
Modified: 2024-11-05T17:35:27.493
Link: CVE-2024-51502
Redhat
No data.