Ubuntu 16.04 Lua5.1 Important Denial of Service Vulnerability USN-8262
Summary: Lua could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - lua5.1: Lua is an embeddable scripting language Details: It was discovered that the Lua parser incorrectly handled garbage collection when processing specially crafted Lua scripts. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code.
Summary: Lua could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - lua5.1: Lua is an embeddable scripting language Details: It was discovered that the Lua parser incorrectly handled garbage collection when processing specially crafted Lua scripts. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code.
The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS liblua5.1-0 5.1.5-8ubuntu1+esm1 Available with Ubuntu Pro lua5.1 5.1.5-8ubuntu1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.
The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS liblua5.1-0 5.1.5-8ubuntu1+esm1 Available with Ubuntu Pro lua5.1 5.1.5-8ubuntu1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
