Описание
Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Ceph Storage 3 | ceph | Affected | ||
Red Hat Enterprise Linux 6 | lua | Not affected | ||
Red Hat Enterprise Linux 7 | lua | Not affected | ||
Red Hat JBoss Web Server 5 | lua | Not affected | ||
Red Hat Enterprise Linux 8 | lua | Fixed | RHSA-2019:3706 | 05.11.2019 |
Red Hat Enterprise Linux 8 | lua | Fixed | RHSA-2019:3706 | 05.11.2019 |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.
Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.
Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For examp ...
7.5 High
CVSS3