Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-6706

Опубликовано: 23 янв. 2019
Источник: debian
EPSS Низкий

Описание

Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lua5.3fixed5.3.6-1package
lua5.3fixed5.3.3-1.1+deb11u1bullseyepackage
lua5.2not-affectedpackage
lua5.1not-affectedpackage
lua50not-affectedpackage

Примечания

  • http://lua-users.org/lists/lua-l/2019-01/msg00039.html

  • lua50 and lua5.1 don't have the affected code.

  • lua5.2 is not vulnerable as it doesn't free the value before using it.

  • https://github.com/lua/lua/commit/89aee84cbc9224f638f3b7951b306d2ee8ecb71e (v5.3.6)

EPSS

Процентиль: 78%
0.01247
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.

CVSS3: 7.5
redhat
больше 6 лет назад

Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.

CVSS3: 7.5
nvd
больше 6 лет назад

Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.

suse-cvrf
около 6 лет назад

Security update for lua53

suse-cvrf
больше 6 лет назад

Security update for lua53

EPSS

Процентиль: 78%
0.01247
Низкий