Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-43519

Опубликовано: 09 нояб. 2021
Источник: redhat
CVSS3: 5.5

Описание

Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.

A stack overflow issue was discovered in Lua in the lua_resume() function of 'ldo.c'. This flaw allows a local attacker to pass a specially crafted file to the Lua Interpreter, causing a crash that leads to a denial of service.

Отчет

This vulnerability does not affect Red Hat Enterprise Linux 8, because code-base was completely rewritten between 5.3 and 5.4. So, RHEL-8 is unlikely to be affected by this or a similar issue. This flaw is marked as Out-of-Support-Scope for Red Hat Enterprise Linux 6 and 7 because the flaw impact is moderate. For additional information, refer to the Red Hat Enterprise Linux Life Cycle & Update Policy: https://access.redhat.com/support/policy/updates/errata/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6luaOut of support scope
Red Hat Enterprise Linux 7luaOut of support scope
Red Hat Enterprise Linux 8libreoffice:flatpak/luaNot affected
Red Hat Enterprise Linux 8luaNot affected
Red Hat JBoss Core ServicesluaNot affected
Red Hat Enterprise Linux 9luaFixedRHSA-2023:095728.02.2023
Red Hat Enterprise Linux 9luaFixedRHSA-2023:095728.02.2023
Red Hat Enterprise Linux 9.0 Extended Update SupportluaFixedRHSA-2023:121114.03.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2047672lua: stack overflow in lua_resume of ldo.c allows a DoS via a crafted script file

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 3 лет назад

Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.

CVSS3: 5.5
nvd
больше 3 лет назад

Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.

CVSS3: 5.5
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 5.5
debian
больше 3 лет назад

Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 a ...

CVSS3: 5.5
github
около 3 лет назад

Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.

5.5 Medium

CVSS3