cbcvebase.
CVE-2018-11219
published 2018-06-17

CVE-2018-11219: An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2, leading…

critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2, leading to a failure of bounds checking.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianredis< redis 5:4.0.10-1 (bookworm)redis 5:4.0.10-1 (bookworm)
oraclecommunications_operations_monitor
oraclecommunications_operations_monitor
redhatopenstack
redhatopenstack
redisredis>= 0 < 5:4.0.10-15:4.0.10-1
redisredis>= 0 < 5:4.0.10-15:4.0.10-1
redisredis>= 0 < 5:4.0.10-15:4.0.10-1
redisredis>= 0 < 5:4.0.10-15:4.0.10-1
redislabsredis< 3.2.123.2.12
redislabsredis
redislabsredis>= 4.0 < 4.0.104.0.10

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL