Name
CVE-2014-5461
Description
Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments.
CWEs
Published Date
Updated Date
Workaround
-
Advisories
http://advisories.mageia.org/MGASA-2014-0414.htmlThird Party Advisory
http://lists.opensuse.org/opensuse-updates/2014-09/msg00030.htmlThird Party Advisory
http://www.debian.org/security/2014/dsa-3015Third Party Advisory
http://www.debian.org/security/2014/dsa-3016Third Party Advisory
http://www.ubuntu.com/usn/USN-2338-1Third Party Advisory
http://advisories.mageia.org/MGASA-2014-0414.htmlThird Party Advisory
http://lists.opensuse.org/opensuse-updates/2014-09/msg00030.htmlThird Party Advisory
http://www.debian.org/security/2014/dsa-3015Third Party Advisory
http://www.debian.org/security/2014/dsa-3016Third Party Advisory
http://www.ubuntu.com/usn/USN-2338-1Third Party Advisory
Analysis#
Vulnerability Rating#
5
CVSSv2
Others affected components#
Resolved with patches#
lua (buildroot:2025.02.x)
#
Title
Author
Resolve
1
Fix stack overflow in vararg functions
Enrico Tassi <gareuselesinge@debian.org>
CVE-2014-5461
lua (buildroot:master)
#
Title
Author
Resolve
1
Fix stack overflow in vararg functions
Enrico Tassi <gareuselesinge@debian.org>
CVE-2014-5461
lua (openwrt:master)
#
Title
Author
Resolve
1
Fix stack overflow in vararg functions
Enrico Tassi <gareuselesinge@debian.org>
CVE-2014-5461
lua (openwrt:openwrt-25.12)
#
Title
Author
Resolve
1
Fix stack overflow in vararg functions
Enrico Tassi <gareuselesinge@debian.org>
CVE-2014-5461