CVE-2023-4540
Summary
| CVE | CVE-2023-4540 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-05 08:15:00 UTC |
| Updated | 2023-10-13 01:30:00 UTC |
| Description | Improper Handling of Exceptional Conditions vulnerability in Daurnimator lua-http library allows Excessive Allocation and a denial of service (DoS) attack to be executed by sending a properly crafted request to the server.
This issue affects lua-http: all versions before commit ddab283. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Nie znaleziono strony | CERT Polska |
MISC |
cert.pl |
|
| https/cert.pl/en/posts/2023/09/CVE-2023-4540 |
MISC |
https |
|
| http/h1_stream: handle EOF when `body_read_type==length` · daurnimator/lua-http@ddab283 · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 503370 Alpine Linux Security Update for lua-http
- 506115 Alpine Linux Security Update for lua-http