Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "liblua5.1-0", "binary_version": "5.1.5-5ubuntu0.1" }, { "binary_name": "liblua5.1-0-dev", "binary_version": "5.1.5-5ubuntu0.1" }, { "binary_name": "lua5.1", "binary_version": "5.1.5-5ubuntu0.1" } ] }