Skip to content

[Security] lua used in this project is vulnerable #555

@the-Chain-Warden-thresh

Description

CVE-2020-24370 is a security vulnerability in lua. Although the CVE decription in NVD said that this CVE only affected lua 5.4.0, according to lua this CVE actually existed since lua 5.2. The root cause of this CVE is the negation overflow that occurs when you try to take the negative of 0x80000000. Thus, this CVE also exists in this project. The file which contains vulnerable functions is lua/src/ldebug.c.
You can easily fix this vulnerability by referring to this patch.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions