SB2018120425 - Heap use-after-free in lua5.3 (Alpine package)
Published: December 4, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Heap use-after-free (CVE-ID: CVE-2019-6706)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a geap use-after-free error in lua_upvaluejoin in lapi.c. A remote attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships can cause the service to crash.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=dd508687ca234b47651455c15b64b4e6263f20d5
- https://git.alpinelinux.org/aports/commit/?id=145a4f50eed17c1f3776a9ba77ea45fd38a620ed
- https://git.alpinelinux.org/aports/commit/?id=7571f6ce08088d0644c95da6b1c4a780078951a8
- https://git.alpinelinux.org/aports/commit/?id=7ad58d2fec12ba6086e2774460d4bfe9e91471a9
- https://git.alpinelinux.org/aports/commit/?id=ebd55722b9637f4559c94b13e5e061ffef9fb4a3
- https://git.alpinelinux.org/aports/commit/?id=fda894f6c300cc264f5ca3fb93f499fe51a15750
- https://git.alpinelinux.org/aports/commit/?id=23eacac21afa63d71f78d619df4ce5e0b728051d