lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectgarbage.
ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).
In Lua 5.4.3, an erroneous finalizer called during a tail call leads to a heap-based buffer over-read.
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Lua 5.4.0 (fixed in 5.4.1) has a segmentation fault in changedline in ldebug.c (e.g., when called by luaGtraceexec) because it incorrectly expects that an oldpc value is always updated upon a return of the flow of control to a function.
Stack overflow in luaresume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.
ldebug.c in Lua 5.4.0 attempts to access debug information via the line hook of a stripped function, leading to a NULL pointer dereference.
Lua through 5.4.0 allows a stack redzone cross in luaOpushvfstring because a protection mechanism wrongly calls luaDcallnoyield twice in a row.
Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-based buffer over-read, or use-after-free.
Lua 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient number of list members.
Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of service.
An issue was discovered in Prosody before 0.11.9. It does not use a constant-time algorithm for comparing certain secret strings when running under Lua 5.2 or later. This can potentially be used in a timing attack to reveal the contents of secret strings to an attacker.
An issue was discovered in Prosody before 0.11.9. Default settings are susceptible to remote unauthenticated denial-of-service (DoS) attacks via memory exhaustion when running under Lua 5.2 or Lua 5.3.
An issue in the component luaGrunerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.
Last updated 29 July 2024
Latest version: 5.4.8
End of life: 9/25/2020, Latest version: 5.3.6
End of life: 9/25/2020, Latest version: 5.3.6
End of life: 3/7/2015, Latest version: 5.2.4
End of life: 3/7/2015, Latest version: 5.2.4
End of life: 2/17/2012, Latest version: 5.1.5
End of life: 2/17/2012, Latest version: 5.1.5
End of life: 6/26/2006, Latest version: 5.0.3
End of life: 6/26/2006, Latest version: 5.0.3
End of life: 7/4/2002, Latest version: 4.0.1
End of life: 7/4/2002, Latest version: 4.0.1
End of life: 2/22/2000, Latest version: 3.2.2
End of life: 2/22/2000, Latest version: 3.2.2