First published: Thu Aug 13 2020(Updated: )
Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a row.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lua Lua | =5.4.0 | |
Fedoraproject Fedora | =33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-24342 is high with a severity value of 7.8.
Lua version 5.4.0 and Fedora version 33 are affected by CVE-2020-24342.
To fix CVE-2020-24342, update your Lua installation to a version that includes the patch provided in the reference links.
You can find more information about CVE-2020-24342 in the reference links provided.
The CWE ID of CVE-2020-24342 is 119.