Vulnerability Description
Improper Handling of Exceptional Conditions vulnerability in Daurnimator lua-http library allows Excessive Allocation and a denial of service (DoS) attack to be executed by sending a properly crafted request to the server. Such a request causes the program to enter an infinite loop. This issue affects lua-http: all versions before commit ddab283.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Daurnimator | Lua-Http | 0.4 |
Related Weaknesses (CWE)
References
- https://cert.pl/en/posts/2023/09/CVE-2023-4540/
- https://cert.pl/posts/2023/09/CVE-2023-4540/PatchThird Party Advisory
- https://github.com/daurnimator/lua-http/commit/ddab2835c583d45dec62680ca8d3cbde5Patch
- https://cert.pl/posts/2023/09/CVE-2023-4540/PatchThird Party Advisory
- https://github.com/daurnimator/lua-http/commit/ddab2835c583d45dec62680ca8d3cbde5Patch
- https://https://cert.pl/en/posts/2023/09/CVE-2023-4540/
FAQ
What is CVE-2023-4540?
CVE-2023-4540 is a vulnerability with a CVSS score of 7.5 (HIGH). Improper Handling of Exceptional Conditions vulnerability in Daurnimator lua-http library allows Excessive Allocation and a denial of service (DoS) attack to be executed by sending a properly crafted ...
How severe is CVE-2023-4540?
CVE-2023-4540 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-4540?
Check the references section above for vendor advisories and patch information. Affected products include: Daurnimator Lua-Http.