CVE-2014-5461
Publication date 28 August 2014
Last updated 24 July 2024
Ubuntu priority
Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments.
Status
Package | Ubuntu Release | Status |
---|---|---|
lua5.1 | ||
16.04 LTS xenial |
Fixed 5.1.5-5ubuntu1
|
|
14.04 LTS trusty |
Fixed 5.1.5-5ubuntu0.1
|
|
lua5.2 | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
|
lua50 | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |
References
Related Ubuntu Security Notices (USN)
- USN-2338-1
- Lua vulnerability
- 3 September 2014