Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-28805

Опубликовано: 08 апр. 2022
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.

A heap buffer-overflow vulnerability was found in Lua. The flaw occurs due to vulnerable code present in the lparser.c function of Lua that allows the execution of untrusted Lua code into a system, resulting in malicious activity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6luaNot affected
Red Hat Enterprise Linux 7luaNot affected
Red Hat Enterprise Linux 8libreoffice:flatpak/luaNot affected
Red Hat Enterprise Linux 8luaNot affected
Red Hat JBoss Core ServicesluaNot affected
Red Hat Enterprise Linux 9luaFixedRHSA-2023:258209.05.2023
Red Hat Enterprise Linux 9luaFixedRHSA-2023:258209.05.2023

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125

EPSS

Процентиль: 33%
0.00125
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 3 лет назад

singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.

CVSS3: 9.1
nvd
больше 3 лет назад

singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.

CVSS3: 9.1
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 9.1
debian
больше 3 лет назад

singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) ...

CVSS3: 9.1
github
больше 3 лет назад

singlevar in lparser.c in Lua through 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.

EPSS

Процентиль: 33%
0.00125
Низкий

6.2 Medium

CVSS3