[Date Prev][Date Next][Thread Prev][Thread Next]
[Date Index]
[Thread Index]
- Subject: Re: patch for CVE-2020-15888
- From: Sean Conner <sean@...>
- Date: Wed, 28 Jul 2021 13:50:58 -0400
It was thus said that the Great Andrew Gierth once stated:
> >>>>> "aman" == aman agrawal <aman.161089@gmail.com> writes:
>
> aman> Hi Andrew,
> aman> Thanks for the reply.
>
> aman> I'm getting a crash in running the following code (some modification of
> aman> http://lua-users.org/lists/lua-l/2020-07/msg00054.html) in Lua-5.2.2
>
> I think that's likely to be caused by a separate bug, specifically this
> one:
>
> https://www.lua.org/bugs.html#5.2.2-1
>
> which you will note is fixed in later 5.2.x versions. Does 5.2.3 crash
> on that same code?
I was able to verify that version 5.2.2, as released, will crash with that
code (x86-32, Linux system, using "make generic" [1]), but that applying the
patch as listed (for 5.2.2-1) fixes the issue. I was unable to get
subsequent versions of Lua to crash.
-spc
[1] Due to some wonkiness with the readline library on my Linux system