CVE-2020-24370: Integer Underflow
ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).
Other sources
Lua is vulnerable to a denial of service, caused by a negation overflow and segmentation fault in getlocal and setlocal. A remote attacker could exploit this vulnerability to cause a denial of service.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2020-24370.
What is the severity of CVE-2020-24370?
The severity of CVE-2020-24370 is medium.
How does CVE-2020-24370 impact Lua?
CVE-2020-24370 can cause a denial of service in Lua.
How can I fix CVE-2020-24370 in IBM QRadar SIEM 7.5.0 GA?
You can fix CVE-2020-24370 in IBM QRadar SIEM 7.5.0 GA by applying the patch available at [IBM Support](https://www.ibm.com/support/fixcentral/swg/downloadFixes?parent=IBM%20Security&product=ibm/Other+software/IBM+Security+QRadar+SIEM&release=All&platform=Linux&function=fixId&fixids=7.5.0-QRADAR-QRSIEM-20220215133427&includeRequisites=1&includeSupersedes=0&downloadMethod=http&login=true).
How can I fix CVE-2020-24370 in IBM QRadar SIEM 7.4.3 GA - 7.4.3 FP4?
You can fix CVE-2020-24370 in IBM QRadar SIEM 7.4.3 GA - 7.4.3 FP4 by applying the patch available at [IBM Support](https://www.ibm.com/support/fixcentral/swg/downloadFixes?parent=IBM%20Security&product=ibm/Other+software/IBM+Security+QRadar+SIEM&release=All&platform=Linux&function=fixId&fixids=7.4.3-QRADAR-QRSIEM-20220307203834&includeRequisites=1&includeSupersedes=0&downloadMethod=http).
How can I fix CVE-2020-24370 in IBM QRadar SIEM 7.3.3 GA - 7.3.3 FP10?
You can fix CVE-2020-24370 in IBM QRadar SIEM 7.3.3 GA - 7.3.3 FP10 by applying the patch available at [IBM Support](https://www.ibm.com/support/fixcentral/swg/downloadFixes?parent=IBM%20Security&product=ibm/Other+software/IBM%20Security%20QRadar%20Vulnerability%20Manager&release=All&platform=All&function=fixId&fixids=7.3.3-QRADAR-QRSIEM-20220318161607&includeRequisites=1&includeSupersedes=0&downloadMethod=http&source=SAR).