9.8
CVSSv3

CVE-2020-15889

Published: 21/07/2020 Updated: 23/12/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Lua up to and including 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient number of list members.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lua lua 5.4.0

Vendor Advisories

Lua through 540 has a getobjname heap-based buffer over-read because youngcollection in lgcc uses markold for an insufficient number of list members ...