buildroot ▾
›
master ▾
›
vulnerability
›
CVE-2014-5461
Component Overview
Vulnerability Overview
Name
CVE-2014-5461
Source
NVD (
link
)
Debian (
link
)
Description
Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments.
CWEs
CWE-119
Published Date
Sep 4, 2014
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://advisories.mageia.org/MGASA-2014-0414.html
Third Party Advisory
http://lists.opensuse.org/opensuse-updates/2014-09/msg00030.html
Third Party Advisory
http://www.debian.org/security/2014/dsa-3015
Third Party Advisory
http://www.debian.org/security/2014/dsa-3016
Third Party Advisory
http://www.lua.org/bugs.html#5.2.2-1
Patch
http://www.mandriva.com/security/advisories?name=MDVSA-2015:144
Broken Link
http://www.openwall.com/lists/oss-security/2014/08/21/1
Exploit
http://www.openwall.com/lists/oss-security/2014/08/21/4
Exploit
http://www.openwall.com/lists/oss-security/2014/08/27/2
Mailing List
http://www.securityfocus.com/bid/69342
VDB Entry
http://www.ubuntu.com/usn/USN-2338-1
Third Party Advisory
http://advisories.mageia.org/MGASA-2014-0414.html
Third Party Advisory
http://lists.opensuse.org/opensuse-updates/2014-09/msg00030.html
Third Party Advisory
http://www.debian.org/security/2014/dsa-3015
Third Party Advisory
http://www.debian.org/security/2014/dsa-3016
Third Party Advisory
http://www.lua.org/bugs.html#5.2.2-1
Patch
http://www.mandriva.com/security/advisories?name=MDVSA-2015:144
Broken Link
http://www.openwall.com/lists/oss-security/2014/08/21/1
Exploit
http://www.openwall.com/lists/oss-security/2014/08/21/4
Exploit
http://www.openwall.com/lists/oss-security/2014/08/27/2
Mailing List
http://www.securityfocus.com/bid/69342
VDB Entry
http://www.ubuntu.com/usn/USN-2338-1
Third Party Advisory
Analysis
#
Affected Component
Analysis
lua
Exploitable
Vulnerability Rating
#
5
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
lua
buildroot
2025.02.x
5.1.5
Exploitable
lua
openwrt
master
5.1.5-r11
Patched
lua5.3
openwrt
master
5.3.5-r6
Patched
lua5.4
openwrt
master
5.4.7-r1
Patched
lua
openwrt
openwrt-25.12
5.1.5-r11
Patched
lua5.3
openwrt
openwrt-25.12
5.3.5-r6
Patched
lua5.4
openwrt
openwrt-25.12
5.4.7-r1
Patched
lua
yocto
kirkstone
5.4.4
Not Affected
lua
yocto
master
5.5.0
Not Affected
lua
yocto
scarthgap
5.4.6
Not Affected
Resolved with patches
#
lua (buildroot:2025.02.x)
#
Title
Author
Resolve
1
Fix stack overflow in vararg functions
Enrico Tassi <gareuselesinge@debian.org>
CVE-2014-5461
lua (buildroot:master)
#
Title
Author
Resolve
1
Fix stack overflow in vararg functions
Enrico Tassi <gareuselesinge@debian.org>
CVE-2014-5461
lua (openwrt:master)
#
Title
Author
Resolve
1
Fix stack overflow in vararg functions
Enrico Tassi <gareuselesinge@debian.org>
CVE-2014-5461
lua (openwrt:openwrt-25.12)
#
Title
Author
Resolve
1
Fix stack overflow in vararg functions
Enrico Tassi <gareuselesinge@debian.org>
CVE-2014-5461