CVE-2020-24372Out-of-bounds Read in Luajit

CWE-125Out-of-bounds Read9 documents6 sources
Severity
7.5HIGHNVD
EPSS
0.3%
top 47.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 17
Latest updateMay 24

Description

LuaJIT through 2.1.0-beta3 has an out-of-bounds read in lj_err_run in lj_err.c.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/luajit< luajit 2.1.0~beta3+git20210112+dfsg-2 (bookworm)
Debianluajit/luajit< 2.1.0~beta3+dfsg-5.3+deb11u1+3
NVDluajit/luajit2.0.5+1

🔴Vulnerability Details

2
GHSA
GHSA-cf74-x979-rggp: LuaJIT through 22022-05-24
OSV
CVE-2020-24372: LuaJIT through 22020-08-17

📋Vendor Advisories

2
Red Hat
luajit: out-of-bounds read in lj_err_run function in lj_err.c2020-07-13
Debian
CVE-2020-24372: luajit - LuaJIT through 2.1.0-beta3 has an out-of-bounds read in lj_err_run in lj_err.c.2020

💬Community

4
Bugzilla
CVE-2020-24372 luajit: out-of-bounds read in lj_err_run function in lj_err.c2020-08-19
Bugzilla
CVE-2020-24372 luajit: out-of-bounds read in lj_err_run function in lj_err.c [fedora-all]2020-08-19
Bugzilla
CVE-2020-24372 luajit: out-of-bounds read in lj_err_run function in lj_err.c [epel-all]2020-08-19
Bugzilla
CVE-2020-24372 luajit: out-of-bounds read in lj_err_run function in lj_err.c [openstack-rdo]2020-08-19