Msrc Cbl2 Lua 5.3.5-11 On Cbl Mariner 2.0 vulnerabilities
2 known vulnerabilities affecting msrc/cbl2_lua_5.3.5-11_on_cbl_mariner_2.0.
Total CVEs
2
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2020-15888HIGHCVSS 8.82020-07-14
CVE-2020-15888 [HIGH] CWE-125 Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection leading to a heap-based buffer overflow heap-based buffer over-read or use-after-free.
Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection leading to a heap-based buffer overflow heap-based buffer over-read or use-after-free.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially
msrc
CVE-2019-6706HIGHCVSS 7.5PoC2019-01-08
CVE-2019-6706 [HIGH] CWE-416 Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have ce
Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.
FAQ: Is Azure Linux the only Microsoft product t
msrc