Vulnerabilities
Vulnerable Software
Lua:  >> Lua  >> 5.2.3  Security Vulnerabilities
Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.
CVSS Score
5.5
EPSS Score
0.001
Published
2021-11-09
An issue was discovered in Prosody before 0.11.9. It does not use a constant-time algorithm for comparing certain secret strings when running under Lua 5.2 or later. This can potentially be used in a timing attack to reveal the contents of secret strings to an attacker.
CVSS Score
5.9
EPSS Score
0.032
Published
2021-05-13
ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).
CVSS Score
5.3
EPSS Score
0.027
Published
2020-08-17


Contact Us

Shodan ® - All rights reserved