CVE-2019-6706: Use After Free
Lua 5.3.5 has a use-after-free in luaupvaluejoin in lapi.c. For example a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.
Other sources
Lua 5.3.5 has a use-after-free in luaupvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.3.5-8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.3.5-11
Event History
Frequently Asked Questions
What is CVE-2019-6706?
CVE-2019-6706 is a vulnerability in Lua 5.3.5 that allows an attacker to achieve a crash outcome by triggering a debug.upvaluejoin call with certain arguments.
What is the severity of CVE-2019-6706?
The severity of CVE-2019-6706 is high, with a severity score of 7.5.
Which software versions are affected by CVE-2019-6706?
Lua 5.3.5 and Canonical Ubuntu Linux versions 16.04, 18.04, and 18.10 are affected by CVE-2019-6706.
How can an attacker exploit CVE-2019-6706?
An attacker can exploit CVE-2019-6706 by triggering a debug.upvaluejoin call with specific arguments.
Are there any references for CVE-2019-6706?
Yes, you can find references for CVE-2019-6706 at the following links: http://lua-users.org/lists/lua-l/2019-01/msg00039.html, http://packetstormsecurity.com/files/151335/Lua-5.3.5-Use-After-Free.html, and https://access.redhat.com/security/cve/cve-2019-6706.