Vulnerabilities
Vulnerable Software
Lua:  >> Lua  >> 5.4.4  Security Vulnerabilities
An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.
CVSS Score
7.5
EPSS Score
0.002
Published
2022-07-01
singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.
CVSS Score
9.1
EPSS Score
0.001
Published
2022-04-08
An issue was discovered in Prosody before 0.11.9. It does not use a constant-time algorithm for comparing certain secret strings when running under Lua 5.2 or later. This can potentially be used in a timing attack to reveal the contents of secret strings to an attacker.
CVSS Score
5.9
EPSS Score
0.032
Published
2021-05-13


Contact Us

Shodan ® - All rights reserved