ZeroHour

CVE-2018-11218

PoC ×2
CVSS 3.0
9.8 critical
EPSS
59%p99
Published
()
Modified
Description

Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows.

Vendors
redislabsdebianoracleredhat
Products
redis, debian linux, communications operations monitor, openstack
Weakness
CWE-787
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news