Msrc Cm1 Lua 5.3.5-8 On Cbl Mariner 1.0 vulnerabilities
3 known vulnerabilities affecting msrc/cm1_lua_5.3.5-8_on_cbl_mariner_1.0.
Total CVEs
3
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH3
Vulnerabilities
Page 1 of 1
CVE-2020-24342HIGHCVSS 7.82020-08-11
CVE-2020-24342 [HIGH] CWE-119 Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a row.
Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a row.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to ou
msrc
CVE-2020-15888HIGHCVSS 8.82020-07-14
CVE-2020-15888 [HIGH] CWE-125 Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection leading to a heap-based buffer overflow heap-based buffer over-read or use-after-free.
Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection leading to a heap-based buffer overflow heap-based buffer over-read or use-after-free.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially
msrc
CVE-2019-6706HIGHCVSS 7.5PoC2019-01-08
CVE-2019-6706 [HIGH] CWE-416 Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have ce
Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.
FAQ: Is Azure Linux the only Microsoft product t
msrc