CVE-2020-15889 - log back

CVE-2020-15889 edited at 02 Oct 2020 10:57:12
Remote
- Local
+ Remote
CVE-2020-15889 edited at 02 Oct 2020 10:56:40
Type
- Information disclosure
+ Arbitrary code execution
CVE-2020-15889 edited at 29 Jul 2020 20:45:28
Severity
- Unknown
+ High
Remote
- Unknown
+ Local
Type
- Unknown
+ Information disclosure
Description
+ Lua through 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient number of list members.
References
+ http://lua-users.org/lists/lua-l/2020-07/msg00078.html
+ https://github.com/lua/lua/commit/127e7a6c8942b362aa3c6627f44d660a4fb75312
Notes
CVE-2020-15889 created at 29 Jul 2020 20:44:06