| Name | CVE-2014-5461 |
| Description | Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5. ... |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| References | DLA-47-1, DSA-3015-1, DSA-3016-1 |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| lua5.1 (PTS) | bullseye | 5.1.5-8.1 | fixed |
| bookworm | 5.1.5-9 | fixed |
| trixie | 5.1.5-11 | fixed |
| forky, sid | 5.1.5-12 | fixed |
| lua5.2 (PTS) | bullseye | 5.2.4-1.1 | fixed |
| bookworm, trixie | 5.2.4-3 | fixed |
| forky, sid | 5.2.4-4 | fixed |
The information below is based on the following data on fixed versions.
Notes
http://www.lua.org/bugs.html#5.2.2-1
fixed in 5.2.3, see https://bugzilla.redhat.com/show_bug.cgi?id=1132304#c7