Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.703016
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-3016-1)
Summary:The remote host is missing an update for the Debian 'lua5.2' package(s) announced via the DSA-3016-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'lua5.2' package(s) announced via the DSA-3016-1 advisory.

Vulnerability Insight:
A heap-based overflow vulnerability was found in the way Lua, a simple, extensible, embeddable programming language, handles varargs functions with many fixed parameters called with few arguments, leading to application crashes or, potentially, arbitrary code execution.

For the stable distribution (wheezy), this problem has been fixed in version 5.2.1-3+deb7u1.

For the testing distribution (jessie), this problem has been fixed in version 5.2.3-1.

For the unstable distribution (sid), this problem has been fixed in version 5.2.3-1.

We recommend that you upgrade your lua5.2 packages.

Affected Software/OS:
'lua5.2' package(s) on Debian 7.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2014-5461
BugTraq ID: 69342
http://www.securityfocus.com/bid/69342
Debian Security Information: DSA-3015 (Google Search)
http://www.debian.org/security/2014/dsa-3015
Debian Security Information: DSA-3016 (Google Search)
http://www.debian.org/security/2014/dsa-3016
https://security.gentoo.org/glsa/201701-53
https://security.gentoo.org/glsa/202305-23
http://www.mandriva.com/security/advisories?name=MDVSA-2015:144
http://www.openwall.com/lists/oss-security/2014/08/21/1
http://www.openwall.com/lists/oss-security/2014/08/21/4
http://www.openwall.com/lists/oss-security/2014/08/27/2
http://secunia.com/advisories/59890
http://secunia.com/advisories/60869
http://secunia.com/advisories/61411
SuSE Security Announcement: openSUSE-SU-2014:1145 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-09/msg00030.html
http://www.ubuntu.com/usn/USN-2338-1
CopyrightCopyright (C) 2014 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.