Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments.
2014-09-04T17:55:07.763
2025-04-12T10:46:40.837
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | opensuse | opensuse | 12.3 | Yes |
Operating System | opensuse | opensuse | 13.1 | Yes |
Operating System | canonical | ubuntu_linux | 12.04 | Yes |
Operating System | canonical | ubuntu_linux | 14.04 | Yes |
Operating System | debian | debian_linux | 7.0 | Yes |
Application | lua | lua | 5.1 | Yes |
Application | lua | lua | 5.1.1 | Yes |
Application | lua | lua | 5.1.2 | Yes |
Application | lua | lua | 5.1.3 | Yes |
Application | lua | lua | 5.1.4 | Yes |
Application | lua | lua | 5.1.5 | Yes |
Application | lua | lua | 5.2.0 | Yes |
Application | lua | lua | 5.2.1 | Yes |
Application | lua | lua | 5.2.2 | Yes |
Operating System | mageia | mageia | 3.0 | Yes |
Operating System | mageia | mageia | 4.0 | Yes |