Bug 1174371 - (CVE-2020-15889) VUL-1: CVE-2020-15889: lua,lua51,lua53: getobjname heap-based buffer over-read
(CVE-2020-15889)
VUL-1: CVE-2020-15889: lua,lua51,lua53: getobjname heap-based buffer over-read
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.1
Other Other
: P4 - Low : Minor (vote)
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/264074/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2020-07-22 07:51 UTC by Wolfgang Frisch
Modified: 2020-10-27 16:19 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Wolfgang Frisch 2020-07-22 07:51:48 UTC
CVE-2020-15889

Lua through 5.4.0 has a getobjname heap-based buffer over-read because
youngcollection in lgc.c uses markold for an insufficient number of list
members.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-15889
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15889
https://github.com/lua/lua/commit/127e7a6c8942b362aa3c6627f44d660a4fb75312
http://lua-users.org/lists/lua-l/2020-07/msg00078.html
Comment 1 Wolfgang Frisch 2020-07-22 09:10:30 UTC
The bug was introduced in commit f5f3df3bd17fb3489bbd26ab39fe1580a8dbf9c9 which was merged in Lua 5.4.

SUSE:SLE-11:Update   lua       Not affected [1]
SUSE:SLE-12:Update   lua       Not affected [1]
SUSE:SLE-12:Update   lua51     Not affected [1]
SUSE:SLE-15:Update   lua51     Not affected [1]
SUSE:SLE-15:Update   lua53     Not affected [1]
openSUSE:Factory     lua53     Not affected [1]
openSUSE:Factory     lua54     Affected

[1] code not present
Comment 3 Wolfgang Frisch 2020-07-22 10:40:26 UTC
Reassigned to security-team@suse.de
Comment 4 Callum Farmer 2020-07-24 08:01:34 UTC
Reached Factory
https://build.opensuse.org/request/show/821867
Comment 5 Alexandros Toptsoglou 2020-10-27 16:19:52 UTC
Done