Heap-Based Buffer Overflow in Lua 5.4.0 and Earlier Versions
CVE-2020-15888
8.8HIGH
What is CVE-2020-15888?
Lua versions up to 5.4.0 exhibit a vulnerability due to improper handling of stack resizes in relation to garbage collection. This flaw can lead to severe security issues, including heap-based buffer overflows, buffer over-reads, or use-after-free scenarios, allowing potential attackers to exploit the system. Users are advised to review patches and secure their applications to mitigate risks associated with this vulnerability.