Skip to content

Backport CVE-2020-24370's patch#43

Open
the-Chain-Warden-thresh wants to merge 1 commit intoendrazine:masterfrom
the-Chain-Warden-thresh:master
Open

Backport CVE-2020-24370's patch#43
the-Chain-Warden-thresh wants to merge 1 commit intoendrazine:masterfrom
the-Chain-Warden-thresh:master

Conversation

@the-Chain-Warden-thresh
Copy link

CVE-2020-24370 is a security vulnerability in lua. Although the CVE decription in CVE-2020-24370 said that this CVE only affected lua 5.4.0, according to lua this CVE actually existed since lua 5.2. The root cause of this CVE is the negation overflow that occurs when you try to take the negative of 0x80000000. Thus, this CVE also exists in wcc.
Try to backport the fix to the lua in wcc since the original fix is for 5.4 and several functions have been changed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant