5.5
CVSSv3

CVE-2021-44647

Published: 11/01/2022 Updated: 07/11/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

A stack overflow issue exists in Lua in the lua_resume() function of ldo.c. This flaw allows a local malicious user to pass a specially crafted file to the Lua Interpreter, causing a crash that leads to a denial of service. (CVE-2021-43519) A flaw was found in Lua. An SEGV crash in the funcnamefromcode() function in ldebug.c during error handling occurs in __close metamethods. This flaw allows an malicious user to cause a denial of service. (CVE-2021-44647) A heap buffer-overflow vulnerability was found in Lua. The flaw occurs due to vulnerable code present in the lparser.c function of Lua that allows the execution of untrusted Lua code into a system, resulting in malicious activity. (CVE-2022-28805) A vulnerability was found in Lua. During error handling, the luaG_errormsg() component uses slots from EXTRA_STACK. Some errors can recur such as a string overflow while creating an error message in luaG_runerror, or a C-stack overflow before calling the message handler, causing a crash that leads to a denial of service. (CVE-2022-33099)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lua lua 5.4.3

fedoraproject fedora 34

Vendor Advisories

Debian Bug report logs - #1004189 lua54: CVE-2021-44647 Package: src:lua54; Maintainer for src:lua54 is Debian Lua Team <pkg-lua-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 22 Jan 2022 12:15:01 UTC Severity: important Tags: security, upstream Found in version l ...
A stack overflow issue was discovered in Lua in the lua_resume() function of ldoc This flaw allows a local attacker to pass a specially crafted file to the Lua Interpreter, causing a crash that leads to a denial of service (CVE-2021-43519) A flaw was found in Lua An SEGV crash in the funcnamefromcode() function in ldebugc during error handling ...
A stack overflow issue was discovered in Lua in the lua_resume() function of ldoc This flaw allows a local attacker to pass a specially crafted file to the Lua Interpreter, causing a crash that leads to a denial of service (CVE-2021-43519) A flaw was found in Lua An SEGV crash in the funcnamefromcode() function in ldebugc during error handling ...