CVE-2020-24342: Buffer Overflow
Published Aug 13, 2020
·Updated
Lua through 5.4.0 allows a stack redzone cross in luaOpushvfstring because a protection mechanism wrongly calls luaDcallnoyield twice in a row.
Affected Software
3 affected componentsFixes available
Lua Lua=5.4.0
Fedoraproject Fedora=33
Microsoft cm1 lua 5.3.5-8<5.3.5-8
5.3.5-8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.3.5-8
Event History
Aug 13, 2020
CVE Published
via MITRE·06:54 PM
Data Sourced
via MITRE·06:54 PM
Description
Sep 25, 2020
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-24342?
The severity of CVE-2020-24342 is high with a severity value of 7.8.
2
What software is affected by CVE-2020-24342?
Lua version 5.4.0 and Fedora version 33 are affected by CVE-2020-24342.
3
How can I fix CVE-2020-24342?
To fix CVE-2020-24342, update your Lua installation to a version that includes the patch provided in the reference links.
4
Where can I find more information about CVE-2020-24342?
You can find more information about CVE-2020-24342 in the reference links provided.
5
What is the CWE ID of CVE-2020-24342?
The CWE ID of CVE-2020-24342 is 119.