CVE Vulnerabilities

CVE-2023-4540

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Sep 05, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Improper Handling of Exceptional Conditions vulnerability in Daurnimator lua-http library allows Excessive Allocation and a denial of service (DoS) attack to be executed by sending a properly crafted request to the server. Such a request causes the program to enter an infinite loop.

This issue affects lua-http: all versions before commit ddab283.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Lua-http Daurnimator 0.4 (including) 0.4 (including)
Lua-http Ubuntu bionic *
Lua-http Ubuntu lunar *
Lua-http Ubuntu mantic *
Lua-http Ubuntu trusty *
Lua-http Ubuntu xenial *

References