------------------------------------------------------------------------- Debian LTS Advisory DLA-3469-1 [email protected] https://www.debian.org/lts/security/ Guilhem Moulin June 23, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : lua5.3 Version : 5.3.3-1.1+deb10u1 CVE ID : CVE-2019-6706 CVE-2020-24370 Debian Bug : 920321 988734 Issues were found in lua5.3, a powerful, light-weight programming language designed for extending applications, which may result in denial of service. CVE-2019-6706 Fady Osman discovered a heap-user-after-free vulnerability in lua_upvaluejoin() in lapi.c, which might result in denial of service upon calling debug.upvaluejoin() with specific arguments. CVE-2020-24370 Yongheng Chen discovered a negation overflow and segmentation fault issue in getlocal() and setlocal(), as demonstrated by getlocal(3,2^31). For Debian 10 buster, these problems have been fixed in version 5.3.3-1.1+deb10u1. We recommend that you upgrade your lua5.3 packages. For the detailed security status of lua5.3 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/lua5.3 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS