CVE-2020-24372: High severity luajit vulnerability
Published Aug 17, 2020
·Updated
LuaJIT through 2.1.0-beta3 has an out-of-bounds read in ljerrrun in ljerr.c.
Affected Software
4 affected components
LuaJit LuaJIT<=2.0.5
LuaJit LuaJIT=2.1.0-beta1
LuaJit LuaJIT=2.1.0-beta2
LuaJit LuaJIT=2.1.0-beta3
Event History
Aug 17, 2020
CVE Published
via MITRE·04:05 PM
Data Sourced
via MITRE·04:05 PM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-24372?
The severity of CVE-2020-24372 is high.
2
How does CVE-2020-24372 affect LuaJIT?
CVE-2020-24372 affects LuaJIT versions up to and including 2.1.0-beta3.
3
What is the CWE ID of CVE-2020-24372?
The CWE ID of CVE-2020-24372 is 125.
4
Is there a fix available for CVE-2020-24372?
At the moment, there is no known fix available for CVE-2020-24372. It is recommended to update to a version of LuaJIT that is not affected.
5
Where can I find more information about CVE-2020-24372?
You can find more information about CVE-2020-24372 at the following link: [GitHub Issue](https://github.com/LuaJIT/LuaJIT/issues/603)