5.5

CVE-2021-44647

Exploit
Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lua ≫ Lua Version 5.4.3
Fedoraproject ≫ Fedora Version 34
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.42% 0.333
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:N/A:P
CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

https://security.gentoo.org/glsa/202305-23
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P3EMGAQ5Y6GXJLY4K5DUOOEQT4MZ4J4F/
http://lua-users.org/lists/lua-l/2021-11/msg00195.html
Vendor Advisory
Exploit
Mailing List
http://lua-users.org/lists/lua-l/2021-11/msg00204.html
Patch
Vendor Advisory
Mailing List
https://access.redhat.com/security/cve/cve-2021-44647
Third Party Advisory