Описание
Security update for lua53
This update for lua53 fixes the following issues:
Security issue fixed:
- CVE-2019-6706: Fixed a use-after-free bug in the lua_upvaluejoin function of lapi.c (bsc#1123043)
This update was imported from the SUSE:SLE-15:Update update project.
Список пакетов
openSUSE Leap 15.0
liblua5_3-5-5.3.4-lp150.2.3.1
liblua5_3-5-32bit-5.3.4-lp150.2.3.1
lua53-5.3.4-lp150.2.3.1
lua53-devel-5.3.4-lp150.2.3.1
lua53-doc-5.3.4-lp150.2.3.1
Ссылки
- E-Mail link for openSUSE-SU-2019:0175-1
- SUSE Security Ratings
- SUSE Bug 1123043
- SUSE CVE CVE-2019-6706 page
Описание
Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.
Затронутые продукты
openSUSE Leap 15.0:liblua5_3-5-32bit-5.3.4-lp150.2.3.1
openSUSE Leap 15.0:liblua5_3-5-5.3.4-lp150.2.3.1
openSUSE Leap 15.0:lua53-5.3.4-lp150.2.3.1
openSUSE Leap 15.0:lua53-devel-5.3.4-lp150.2.3.1
Ссылки
- CVE-2019-6706
- SUSE Bug 1123043