VDB
CVE-2020-15888
CVE-2020-15888
PUBLISHED
Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-based buffer over-read, or use-after-free.
EPSS 1.25% · 79.7th percentile
Risk Scores
EPSS Score
1.25%
79.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | lua | 5.4.0 |
| Bitnami | lua | 5.4.0 |
Exploit Intelligence
Timeline
- Jul 21, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Jul 21, 2021 CVE Updated
- Aug 24, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
References
- http://lua-users.org/lists/lua-l/2020-07/msg00053.html url
- http://lua-users.org/lists/lua-l/2020-07/msg00054.html url
- http://lua-users.org/lists/lua-l/2020-07/msg00071.html url
- http://lua-users.org/lists/lua-l/2020-07/msg00079.html url
- https://github.com/lua/lua/commit/6298903e35217ab69c279056f925fb72900ce0b7 url
- https://github.com/lua/lua/commit/eb41999461b6f428186c55abd95f4ce1a76217d5 url
- https://nvd.nist.gov/vuln/detail/CVE-2020-15888 url