Lucene search

K
osvGoogleOSV:CVE-2020-15889
HistoryJul 21, 2020 - 10:15 p.m.

CVE-2020-15889

2020-07-2122:15:12
Google
osv.dev
9
lua 5.4.0
getobjname
heap-based
buffer over-read
vulnerability
youngcollection
lgc.c
markold
list members
software

AI Score

7.3

Confidence

Low

EPSS

0.004

Percentile

72.4%

Lua 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient number of list members.

AI Score

7.3

Confidence

Low

EPSS

0.004

Percentile

72.4%