Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3214 | loona is an experimental, HTTP/1.1 and HTTP/2 implementation in Rust on top of io-uring. `loona-hpack` suffers from the same vulnerability as the original `hpack` as documented in issue #11. All users who try to decode untrusted input using the Decoder are vulnerable to this exploit. This issue has been addressed in release version 0.4.3. All users are advised to upgrade. There are no known workarounds for this vulnerability. |
Github GHSA |
GHSA-7vm6-qwh5-9x44 | loona-hpack Panic Vulnerability |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 05 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 04 Nov 2024 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | loona is an experimental, HTTP/1.1 and HTTP/2 implementation in Rust on top of io-uring. `loona-hpack` suffers from the same vulnerability as the original `hpack` as documented in issue #11. All users who try to decode untrusted input using the Decoder are vulnerable to this exploit. This issue has been addressed in release version 0.4.3. All users are advised to upgrade. There are no known workarounds for this vulnerability. | |
| Title | Panic Vulnerability in loona-hpack | |
| Weaknesses | CWE-755 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-11-21T16:24:15.558Z
Reserved: 2024-10-28T14:20:59.339Z
Link: CVE-2024-51502
Updated: 2024-11-05T16:34:06.311Z
Status : Awaiting Analysis
Published: 2024-11-04T23:15:05.070
Modified: 2024-11-21T17:15:22.737
Link: CVE-2024-51502
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA