Debian alert DLA-3469-1 (lua5.3)
| From: | Guilhem Moulin <guilhem@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 3469-1] lua5.3 security update | |
| Date: | Fri, 23 Jun 2023 00:50:46 +0200 | |
| Message-ID: | <ZJTQRuM3NM+cVj+m@debian.org> |
------------------------------------------------------------------------- Debian LTS Advisory DLA-3469-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Guilhem Moulin June 23, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : lua5.3 Version : 5.3.3-1.1+deb10u1 CVE ID : CVE-2019-6706 CVE-2020-24370 Debian Bug : 920321 988734 Issues were found in lua5.3, a powerful, light-weight programming language designed for extending applications, which may result in denial of service. CVE-2019-6706 Fady Osman discovered a heap-user-after-free vulnerability in lua_upvaluejoin() in lapi.c, which might result in denial of service upon calling debug.upvaluejoin() with specific arguments. CVE-2020-24370 Yongheng Chen discovered a negation overflow and segmentation fault issue in getlocal() and setlocal(), as demonstrated by getlocal(3,2^31). For Debian 10 buster, these problems have been fixed in version 5.3.3-1.1+deb10u1. We recommend that you upgrade your lua5.3 packages. For the detailed security status of lua5.3 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/lua5.3 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
