Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments.
{ "binaries": [ { "binary_version": "5.1.5-5ubuntu0.1", "binary_name": "liblua5.1-0" }, { "binary_version": "5.1.5-5ubuntu0.1", "binary_name": "liblua5.1-0-dev" }, { "binary_version": "5.1.5-5ubuntu0.1", "binary_name": "lua5.1" } ], "availability": "No subscription required" }