Logo
vulnerabilityCVE-2014-5461
Name
CVE-2014-5461
Source
NVD ( link)Debian ( link)
Description
Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
lua
Patched
lua5.3
Patched
lua5.4
Patched

Vulnerability Rating#


5
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
5.1.5
Exploitable
buildroot
master
5.1.5
Exploitable
openwrt
openwrt-25.12
5.1.5-r11
Patched
openwrt
openwrt-25.12
5.3.5-r6
Patched
openwrt
openwrt-25.12
5.4.7-r1
Patched
yocto
kirkstone
5.4.4
Not Affected
yocto
master
5.5.0
Not Affected
yocto
scarthgap
5.4.6
Not Affected

Resolved with patches#


lua (buildroot:2025.02.x)

#
Title
Author
Resolve
1
Fix stack overflow in vararg functions
Enrico Tassi <gareuselesinge@debian.org>
CVE-2014-5461

lua (buildroot:master)

#
Title
Author
Resolve
1
Fix stack overflow in vararg functions
Enrico Tassi <gareuselesinge@debian.org>
CVE-2014-5461

lua (openwrt:master)

#
Title
Author
Resolve
1
Fix stack overflow in vararg functions
Enrico Tassi <gareuselesinge@debian.org>
CVE-2014-5461

lua (openwrt:openwrt-25.12)

#
Title
Author
Resolve
1
Fix stack overflow in vararg functions
Enrico Tassi <gareuselesinge@debian.org>
CVE-2014-5461