[Date Prev][Date Next][Thread Prev][Thread Next]
[Date Index]
[Thread Index]
- Subject: Re: Finalizers and Lua.org demo page
- From: Mikhail Zaycev <zajcev.m@...>
- Date: Thu, 27 Jul 2017 08:50:30 +0300
"Lua does not check the consistency of binary chunks. Maliciously crafted binary chunks can crash the interpreter."
(https://www.lua.org/manual/5.3/manual.html#pdf-load)
I think, load() should not be available to user. Potentially it is as dangerous as os.execute().
- References:
- Finalizers and Lua.org demo page, Egor Skriptunoff
- Re: Finalizers and Lua.org demo page, Luiz Henrique de Figueiredo
- Re: Finalizers and Lua.org demo page, Luiz Henrique de Figueiredo
- Re: Finalizers and Lua.org demo page, Luiz Henrique de Figueiredo
- Re: Finalizers and Lua.org demo page, Luiz Henrique de Figueiredo
- Re: Finalizers and Lua.org demo page, Egor Skriptunoff
- Re: Finalizers and Lua.org demo page, Mikhail Zajcev
- Re: Finalizers and Lua.org demo page, Egor Skriptunoff
- Re: Finalizers and Lua.org demo page, Mikhail Zajcev
- Re: Finalizers and Lua.org demo page, Egor Skriptunoff
- Re: Finalizers and Lua.org demo page, Mikhail Zajcev
- Re: Finalizers and Lua.org demo page, Egor Skriptunoff
- Re: Finalizers and Lua.org demo page, Mikhail Zajcev
- Re: Finalizers and Lua.org demo page, Egor Skriptunoff