CVE-2019-6706
23.01.2019, 19:29
Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.Enginsight
Vendor | Product | Version |
---|---|---|
lua | lua | 5.3.5 |
canonical | ubuntu_linux | 16.04 |
canonical | ubuntu_linux | 18.04 |
canonical | ubuntu_linux | 18.10 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||
---|---|---|---|---|---|---|---|---|---|
lua5.1 |
| ||||||||
lua5.2 |
| ||||||||
lua5.3 |
| ||||||||
lua50 |
|

Ubuntu Releases
Ubuntu Product | |||||||||
---|---|---|---|---|---|---|---|---|---|
lua5.1 |
| ||||||||
lua5.2 |
| ||||||||
lua5.3 |
| ||||||||
lua50 |
|
Common Weakness Enumeration
References