CVE-2019-6706
Summary
| CVE | CVE-2019-6706 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-01-23 19:29:00 UTC |
| Updated | 2023-06-23 01:15:00 UTC |
| Description | Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| CVE-2019-6706 - Red Hat Customer Portal |
MISC |
access.redhat.com |
|
| Lua-l - [Bug Report] Use after free in debug.upvaluejoin | List View |
MISC |
lua.2524044.n2.nabble.com |
Exploit, Issue Tracking, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| Lua 5.3.5 - 'debug.upvaluejoin' Use After Free - Multiple dos Exploit |
EXPLOIT-DB |
www.exploit-db.com |
Exploit, Patch, Third Party Advisory, VDB Entry |
| USN-3941-1: Lua vulnerability | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| [Bug Report] Use after free in debug.upvaluejoin |
MISC |
lua-users.org |
|
| [SECURITY] [DLA 3469-1] lua5.3 security update |
MLIST |
lists.debian.org |
|
| Fixed bug in 'lua_upvaluejoin' · lua/lua@89aee84 · GitHub |
MISC |
github.com |
|
| cve-analysis/CVE-2019-6706.pdf at a43c9ccd00274b31fa2f24c6c8f20ce36655682d · Lua-Project/cve-analysis · GitHub |
MISC |
github.com |
|
| Lua 5.3.5 Use-After-Free ≈ Packet Storm |
MISC |
packetstormsecurity.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296071 Oracle Solaris 11.4 Support Repository Update (SRU) 27.82.1 Missing (CPUOCT2020)
- 500556 Alpine Linux Security Update for lua5.3
- 501751 Alpine Linux Security Update for lua5.4
- 504124 Alpine Linux Security Update for lua5.3
- 504125 Alpine Linux Security Update for lua5.4
- 6000153 Debian Security Update for lua5.3 (DLA 3469-1)
- 900048 CBL-Mariner Linux Security Update for lua 5.3.5
- 901011 Common Base Linux Mariner (CBL-Mariner) Security Update for lua (6669-1)
- 903062 Common Base Linux Mariner (CBL-Mariner) Security Update for lua (2654)
- 940062 AlmaLinux Security Update for lua (ALSA-2019:3706)
- 960769 Rocky Linux Security Update for lua (RLSA-2019:3706)