cve/2015/CVE-2015-0228.md
2024-06-18 02:51:15 +02:00

1.1 KiB

CVE-2015-0228

Description

The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Ping frame after a Lua script has called the wsupgrade function.

POC

Reference

Github