CVE-2020-24342: Buffer Overflow
Published Aug 13, 2020
·Updated
Lua through 5.4.0 allows a stack redzone cross in luaOpushvfstring because a protection mechanism wrongly calls luaDcallnoyield twice in a row.
Affected Software
2 affected components
Lua LPeg=5.4.0
fedoraproject fedora=33
Remediation
Event History
Aug 13, 2020
CVE Published
via MITRE·06:54 PM
Data Sourced
via MITRE·06:54 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-24342?
The severity of CVE-2020-24342 is high with a severity value of 7.8.
2
What software is affected by CVE-2020-24342?
Lua version 5.4.0 and Fedora version 33 are affected by CVE-2020-24342.
3
How can I fix CVE-2020-24342?
To fix CVE-2020-24342, update your Lua installation to a version that includes the patch provided in the reference links.
4
Where can I find more information about CVE-2020-24342?
You can find more information about CVE-2020-24342 in the reference links provided.
5
What is the CWE ID of CVE-2020-24342?
The CWE ID of CVE-2020-24342 is 119.