PT-2018-2776 · Redis+2 · Redis+2

Published

2018-06-13

·

Updated

2021-08-04

·

CVE-2018-11219

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Redis versions prior to 3.2.12 Redis versions 4.x prior to 4.0.10 Redis versions 5.x prior to 5.0 RC2
Description An Integer Overflow issue was discovered in the struct library in the Lua subsystem, leading to a failure of bounds checking. This issue may allow a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For Redis versions prior to 3.2.12, update to version 3.2.12 or later. For Redis versions 4.x prior to 4.0.10, update to version 4.0.10 or later. For Redis versions 5.x prior to 5.0 RC2, update to version 5.0 RC2 or later.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1906
BDU:2019-01774
CVE-2018-11219
DLA-1396-1
DSA-4230-1
MGASA-2018-0309
OPENSUSE-SU-2018_1802-1
RHSA-2019:0052
RHSA-2019:0094
RHSA-2019:1860
SUSE-OU-2020:3291-1

Affected Products

Alt Linux
Redis
Suse