Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Lua 缓冲区错误漏洞
Vulnerability Description
Lua是LUA团队的一款轻量级、扩展的开源脚本语言。 Lua 5.4.4及之前版本存在缓冲区错误漏洞,该漏洞源于 lparser.c 中的 singlevar 缺少特定的 luaK_exp2anyregup 调用,导致基于堆的缓冲区过度读取,这可能会影响编译不受信任的 Lua 代码的系统。
CVSS Information
N/A
Vulnerability Type
N/A