8.8
CVSSv3

CVE-2020-15888

Published: 21/07/2020 Updated: 16/05/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Lua up to and including 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-based buffer over-read, or use-after-free.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lua lua 5.4.0

Vendor Advisories

Debian Bug report logs - #972101 CVE-2020-15888 Package: lua54; Maintainer for lua54 is Debian Lua Team <pkg-lua-devel@listsaliothdebianorg>; Source for lua54 is src:lua54 (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 12 Oct 2020 18:12:04 UTC Severity: important Tags: secur ...
Lua through 540 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-based buffer over-read, or use-after-free ...