LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame traversal is mishandled.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade luajit | Oct 1, 2024 | Jul 21, 2020 |
| Debian | — | Upgrade luajit | Jul 30, 2020 | Jul 21, 2020 |
| Ubuntu | — | Upgrade luajitUpgrade libluajit-5.1-2Upgrade libluajit-5.1-commonUpgrade libluajit-5.1-dev | Sep 16, 2020 | Jul 21, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub