Login
Newsletter
Werbung

Sicherheit: Denial of Service in Lua
Aktuelle Meldungen Distributionen
Name: Denial of Service in Lua
ID: USN-3941-1
Distribution: Ubuntu
Plattformen: Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 18.10
Datum: Mo, 8. April 2019, 20:58
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6706
Applikationen: Lua

Originalnachricht


--===============0965940549849058455==
Content-Type: multipart/signed; micalg="pgp-sha256";
protocol="application/pgp-signature";
boundary="=-AK/HUGS6clKcD0XmWKMX"


--=-AK/HUGS6clKcD0XmWKMX
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-3941-1
April 08, 2019

lua5.3 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.10
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

Lua could be made to crash if it received a specially crafted script.

Software Description:
- lua5.3: Simple, extensible, embeddable programming language

Details:

Fady Othman discovered that Lua incorrectly handled certain scripts.
An attacker could possibly use this issue to cause a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.10:
lua5.3 5.3.3-1ubuntu0.18.10.1

Ubuntu 18.04 LTS:
lua5.3 5.3.3-1ubuntu0.18.04.1

Ubuntu 16.04 LTS:
lua5.3 5.3.1-1ubuntu2.1

In general, a standard system update will make all the necessary
changes.

References:
https://usn.ubuntu.com/usn/usn-3941-1
CVE-2019-6706

Package Information:
https://launchpad.net/ubuntu/+source/lua5.3/5.3.3-1ubuntu0.18.10.1
https://launchpad.net/ubuntu/+source/lua5.3/5.3.3-1ubuntu0.18.04.1
https://launchpad.net/ubuntu/+source/lua5.3/5.3.1-1ubuntu2.1
--=-AK/HUGS6clKcD0XmWKMX
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAABCAAGBQJcq4smAAoJEEW851uECx9pDBEQAIxQbsMu4ycCSfd2akZ5/Ter
glU6ldItFxAPPDpJPzU4AQ0/maR2r9zdcIwm4FAuxpw6ie0CKNzvU1uxoiXOSmeg
Uv09KSkgjUQD6BC5iJ/OYu5fvaRVHvPjc0JvWHmci4d7GLcjzujbl240qKSpYU8o
u0iia8eIIS27whbBsVoAQ3dsglvwQzV19tS9EopyNGDdc2gw+4pAv5XHuz+Or9uM
pGDWFujqYpwgmX56xUnQmcXv9g6rXloOK/cPXsz39gJTkMeI5AZibw6rW8wdrfEe
egANJhH5hVKfWHDnBOyC51UbLSA7n+oqp/3CiAfiFs61hjmu3sPai2SNipKhih1J
iIand3xnXX8zJTuVHUnxDBLi6t/5jwsFtoJ/XnIJdTAqhk/3U3MDUbeuhnWSV/Zx
I1B8UnRCslHxLKrj+D1vmrCcn3rKfi0r6Rv7KT0+FrTDPWDMZkpENF4yBUH7KwdQ
BIgfpA+J5lYll9PFHUCtCOXNqQrE265mLdXZ0gmHzNIVj/SyA7whgF/6mG7AmHls
VfVLueY16f38mVPpji1qHOrq8tdCXeL0y7uIt7sLjYF1pVartx1a15KkEbkQBOOZ
e9NpJwRWHcAZy/SF4pWiiumYr7sJCmhfb1HleStniPMmluMW/ImRx8+iyj5V/GQB
eF+RDH6IaGPErNEvhqmr
=KPOw
-----END PGP SIGNATURE-----

--=-AK/HUGS6clKcD0XmWKMX--



--===============0965940549849058455==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5
LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl
IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj
dXJpdHktYW5ub3VuY2UK

--===============0965940549849058455==--
Pro-Linux
Traut euch!
Neue Nachrichten
Werbung