First published: Fri Apr 08 2022(Updated: )
Last updated 29 July 2024
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lua Lua | >=5.4.0<=5.4.4 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 | |
Lua Lua | >=5.4.0<5.4.5 | |
debian/lua5.1 | 5.1.5-8.1 5.1.5-9 | |
debian/lua5.2 | 5.2.4-1.1 5.2.4-3 | |
debian/lua5.3 | 5.3.3-1.1+deb11u1 5.3.6-2 | |
debian/lua5.4 | <=5.4.2-2 | 5.4.4-3+deb12u1 5.4.6-3 |
debian/lua50 | 5.0.3-8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-28805.
The severity of CVE-2022-28805 is critical with a CVSS score of 9.1.
Lua versions from 5.4.0 up to (excluding) 5.4.4 are affected by CVE-2022-28805.
Systems with Lua versions from 5.4.0 up to (excluding) 5.4.4 are affected by CVE-2022-28805. Additionally, Fedora 35 and Fedora 36 are also affected.
CVE-2022-28805 can be exploited by compiling untrusted Lua code, leading to a heap-based buffer over-read.