Logo
vulnerabilityCVE-2023-4540
Name
CVE-2023-4540
Source
NVD ( link)Debian ( link)
Description
Improper Handling of Exceptional Conditions vulnerability in Daurnimator lua-http library allows Excessive Allocation and a denial of service (DoS) attack to be executed by sending a properly crafted request to the server. Such a request causes the program to enter an infinite loop. This issue affects lua-http: all versions before commit ddab283.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
lua-http
Patched

Vulnerability Ratings#


7.5
CVSSv31
7.5
CVSSv31
NaN
other

Others affected component#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
0.4-0
Patched

Resolved with patches#


lua-http (buildroot:2025.02.x)

#
Title
Author
Resolve
1
http/h1_stream: handle EOF when `body_read_type==length`
daurnimator <quae@daurnimator.com>
CVE-2023-4540

lua-http (buildroot:master)

#
Title
Author
Resolve
1
http/h1_stream: handle EOF when `body_read_type==length`
daurnimator <quae@daurnimator.com>
CVE-2023-4540