{ "id": "openEuler-SA-2022-1632", "url": "https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2022-1632", "title": "An update for lua is now available for openEuler-22.03-LTS", "severity": "Critical", "description": "Lua is a powerful, efficient, lightweight, embeddable scripting language. It supports procedural programming, object-oriented programming, functional programming, data-driven programming, and data description.\r\n\r\nSecurity Fix(es):\r\n\r\nsinglevar in lparser.c in Lua through 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.(CVE-2022-28805)\n\nLua 5.4.4 and 5.4.2 are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of service.(CVE-2021-44647)", "cves": [ { "id": "CVE-2021-44647", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-44647", "severity": "Critical" } ] }