cbcvebase.
CVE-2018-11218
published 2018-06-17

CVE-2018-11218: Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of…

critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EXPLOIT
Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianredis< redis 5:4.0.10-1 (bookworm)redis 5:4.0.10-1 (bookworm)
oraclecommunications_operations_monitor
oraclecommunications_operations_monitor
redhatopenstack
redhatopenstack
redisredis>= 0 < 5:4.0.10-15:4.0.10-1
redisredis>= 0 < 5:4.0.10-15:4.0.10-1
redisredis>= 0 < 5:4.0.10-15:4.0.10-1
redisredis>= 0 < 5:4.0.10-15:4.0.10-1
redislabsredis< 3.2.123.2.12
redislabsredis
redislabsredis>= 4.0 < 4.0.104.0.10

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL