CVE ID | CVE-2023-4540 |
Publication date | 05 September 2023 |
Vendor | Daurnimator |
Product | lua-http |
Vulnerable versions | All including 0.4 before ddab283 commit |
Vulnerability type (CWE) | Loop with Unreachable Exit Condition ('Infinite Loop') (CWE-835) |
Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in the lua-http library and participated in its coordination. The vulnerability allows a denial of service (DoS) attack to be executed by sending a properly crafted request to the server. Such a request causes the program to enter an infinite loop.
The vulnerability has been confirmed by the vendor and fixed. Vulnerable are all versions, including 0.4 before commit ddab283. The vulnerability has been assigned the number CVE-2023-4540.
Credits
We thank Artur Łącki for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.