CVE-2020-15888
HIGH8.8EPSS 1.2%Published: 7/21/2020Modified: 4/28/2026
Also known as:DEBIAN-CVE-2020-15888
Description
Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-based buffer over-read, or use-after-free.
Affected packages (2)
- Bitnami/lua>= 5.4.0, < 5.4.1
- Debian/lua5.4from 0, < 5.4.1-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
References (8)
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2020-15888
- WEBhttp://lua-users.org/lists/lua-l/2020-07/msg00053.html
- WEBhttp://lua-users.org/lists/lua-l/2020-07/msg00054.html
- WEBhttp://lua-users.org/lists/lua-l/2020-07/msg00071.html
- WEBhttp://lua-users.org/lists/lua-l/2020-07/msg00079.html
- WEBhttps://github.com/lua/lua/commit/6298903e35217ab69c279056f925fb72900ce0b7
- WEBhttps://github.com/lua/lua/commit/eb41999461b6f428186c55abd95f4ce1a76217d5
- WEBhttps://nvd.nist.gov/vuln/detail/CVE-2020-15888