CVE

CVE-2020-15889

CVE-2020-15889

Lua through 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient number of list members.

Source: CVE-2020-15889

Exit mobile version