Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-33099

Опубликовано: 01 июл. 2022
Источник: redhat
CVSS3: 6.5

Описание

An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.

A vulnerability was found in Lua. During error handling, the luaG_errormsg() component uses slots from EXTRA_STACK. Some errors can recur such as a string overflow while creating an error message in 'luaG_runerror', or a C-stack overflow before calling the message handler, causing a crash that leads to a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6luaNot affected
Red Hat Enterprise Linux 7luaNot affected
Red Hat Enterprise Linux 8libreoffice:flatpak/luaNot affected
Red Hat Enterprise Linux 8luaNot affected
Red Hat JBoss Core ServicesluaNot affected
Red Hat Enterprise Linux 9luaFixedRHSA-2022:732902.11.2022
Red Hat Enterprise Linux 9luaFixedRHSA-2022:732902.11.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2104427lua: heap buffer overflow in luaG_errormsg() in ldebug.c due to uncontrolled recursion in error handling

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.

CVSS3: 7.5
nvd
около 3 лет назад

An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.

CVSS3: 7.5
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 7.5
debian
около 3 лет назад

An issue in the component luaG_runerror of Lua v5.4.4 and below leads ...

rocky
почти 3 года назад

Moderate: lua security update

6.5 Medium

CVSS3