Segmentation Fault Vulnerability in Lua 5.4.0: Incorrect Expectation of Updated oldpc Value

Segmentation Fault Vulnerability in Lua 5.4.0: Incorrect Expectation of Updated oldpc Value

CVE-2020-15945 · MEDIUM Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Lua through 5.4.0 has a segmentation fault in changedline in ldebug.c (e.g., when called by luaG_traceexec) because it incorrectly expects that an oldpc value is always updated upon a return of the flow of control to a function.

Learn more about our Web Application Penetration Testing UK.