CVE-2021-45985
CVSS V2 None
CVSS V3 None
Description
In Lua 5.4.3, an erroneous finalizer called during a tail call leads to a heap-based buffer over-read.
Overview
- CVE ID
- CVE-2021-45985
- Assigner
- cve@mitre.org
- Vulnerability Status
- Analyzed
- Published Version
- 2023-04-10T09:15:07
- Last Modified Date
- 2023-04-14T03:51:34
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:lua:lua:5.4.3:*:*:*:*:*:*:* | 1 | OR |
References
Reference URL | Reference Tags |
---|---|
http://lua-users.org/lists/lua-l/2021-12/msg00019.html | Exploit Mailing List Vendor Advisory |
https://github.com/lua/lua/commit/cf613cdc6fa367257fc61c256f63d917350858b5 | Patch |
https://www.lua.org/bugs.html#5.4.3-11 | Vendor Advisory |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2021-45985 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45985 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-04-17 04:25:32 | Added to TrackCVE | |||
2023-04-17 04:25:33 | Weakness Enumeration | new |