Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2023:0957

Опубликовано: 06 апр. 2023
Источник: rocky
Оценка: Moderate

Описание

Moderate: lua security update

The lua packages provide support for Lua, a powerful light-weight programming language designed for extending applications. Lua is also frequently used as a general-purpose, stand-alone language.

Security Fix(es):

  • lua: use after free allows Sandbox Escape (CVE-2021-44964)

  • lua: stack overflow in lua_resume of ldo.c allows a DoS via a crafted script file (CVE-2021-43519)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
lua-libsx86_642.el9_1lua-libs-5.4.4-2.el9_1.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

oracle-oval
больше 2 лет назад

ELSA-2023-0957: lua security update (MODERATE)

CVSS3: 6.3
ubuntu
больше 3 лет назад

Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.

CVSS3: 7
redhat
больше 3 лет назад

Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.

CVSS3: 6.3
nvd
больше 3 лет назад

Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.

CVSS3: 6.3
msrc
больше 3 лет назад

Описание отсутствует