cbcvebase.
CVE-2018-11219
published 2018-06-17

CVE-2018-11219: An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2, leading…

PriorityP347critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
7.06%
93.5th percentile
An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2, leading to a failure of bounds checking.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianredis< redis 5:4.0.10-1 (bookworm)redis 5:4.0.10-1 (bookworm)
oraclecommunications_operations_monitor
oraclecommunications_operations_monitor
redhatopenstack
redhatopenstack
redisredis>= 0 < 5:4.0.10-15:4.0.10-1
redisredis>= 0 < 5:4.0.10-15:4.0.10-1
redisredis>= 0 < 5:4.0.10-15:4.0.10-1
redisredis>= 0 < 5:4.0.10-15:4.0.10-1
redislabsredis< 3.2.123.2.12
redislabsredis
redislabsredis>= 4.0 < 4.0.104.0.10

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.