Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-41108.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-41108
Upstream
Published
2014-09-04T17:55:07Z
Modified
2026-04-21T04:29:14.840185Z
Summary
CVE-2014-5461 affecting package ceph for versions less than 18.2.2-1
Details

Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments.

References

Affected packages

Azure Linux:3 / ceph

Package

Name
ceph
Purl
pkg:rpm/azure-linux/ceph

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
18.2.2-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-41108.json"