Skip to content

Conversation

@npt-1707
Copy link

Hi again,

I identified another potential vulnerability in a clone function singlevar() in src/lua/src/lparser.c sourced from lua/lua. This issue, originally reported in CVE-2022-28805, was resolved in the repository via this commit lua/lua@1f3c6f4.

This PR applies the corresponding patch to fix the vulnerability in this codebase.

Please review at your convenience. Thank you!

@mfisher31
Copy link
Member

Hey thanks, but we could just update all of lua to 5.4.7, and it should just work: all that would take is replacing element/src/lua/src with lua-5.4.7/src. Assuming lua didn't change file names or add/remove sources

@CLAassistant
Copy link

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants