Wind River Support Network

HomeDefectsLINCD-2699
Fixed

LINCD-2699 : Security Advisory - lua - CVE-2020-15945

Created: Jul 27, 2020    Updated: May 13, 2022
Resolved Date: Sep 4, 2020
Found In Version: 10.20.6.0
Fix Version: 10.20.39.0
Severity: Standard
Applicable for: Wind River Linux CD
Component/s: Userspace

Description

Lua through 5.4.0 has a segmentation fault in changedline in ldebug.c (e.g., when called by luaG_traceexec) because it incorrectly expects that an oldpc value is always updated upon a return of the flow of control to a function.

CREATE(Triage):(User=admin) CVE-2020-15945 (https://nvd.nist.gov/vuln/detail/CVE-2020-15945)

CVEs


Live chat
Online