CVE-2025-67482: Lua segfault in unpack()
Vulnerability in Wikimedia Foundation Scribunto, Wikimedia Foundation luasandbox. This vulnerability is associated with program files includes/Engines/LuaCommon/lualib/mwInit.Lua, library.C.
This issue affects Scribunto: from before 1.39.16, 1.43.6, 1.44.3, 1.45.1; luasandbox: from before fea2304f8f6ab30314369a612f4f5b165e68e95a.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67482?
CVE-2025-67482 has been classified with a medium severity due to the potential for a segmentation fault in the vulnerable versions of Scribunto and luasandbox.
How do I fix CVE-2025-67482?
To mitigate CVE-2025-67482, upgrade to Scribunto version 1.39.16 or newer, or update luasandbox to version feat2304f8f6ab30314369a612f4f5b165e68e95a or newer.
Which versions are affected by CVE-2025-67482?
CVE-2025-67482 affects Scribunto versions before 1.39.16, 1.43.6, 1.44.3, and 1.45.1, as well as specified versions of luasandbox.
What are the implications of exploiting CVE-2025-67482?
Exploitation of CVE-2025-67482 may lead to application crashes and disruptions due to segmentation faults in the affected components.
Is CVE-2025-67482 specific to any software?
Yes, CVE-2025-67482 specifically affects Wikimedia Foundation's Scribunto and luasandbox libraries.