cbcvebase.
CVE-2015-8080
published 2016-04-13

CVE-2015-8080: Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackers with permission…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly bypass intended sandbox restrictions via a large number, which triggers a stack-based buffer overflow.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianredis< redis 2:3.0.5-4 (bookworm)redis 2:3.0.5-4 (bookworm)
debianredis< redis 5:6.0.0-1 (bookworm)redis 5:6.0.0-1 (bookworm)
msrccbl2_redis_5.0.5-7_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_redis_5.0.5-4_on_cbl_mariner_1.0
opensuseleap
opensuseopensuse
oraclecommunications_operations_monitor
oraclecommunications_operations_monitor
oraclecommunications_operations_monitor
oraclecommunications_operations_monitor
redhatopenstack
redhatopenstack
redisredis>= 0 < 2:3.0.5-42:3.0.5-4
redisredis>= 0 < 5:6.0.0-15:6.0.0-1
redisredis>= 0 < 2:3.0.5-42:3.0.5-4
redisredis>= 0 < 5:6.0.0-15:6.0.0-1
redisredis>= 0 < 2:3.0.5-42:3.0.5-4
redisredis>= 0 < 5:6.0.0-15:6.0.0-1

CVSS provenance

nvdv3.17.7HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
osv7.5HIGH