ZeroHour

CVE-2019-10192

CVSS 3.1
7.2 high
EPSS
26%p98
Published
()
Modified
Description

A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By carefully corrupting a hyperloglog using the SETRANGE command, an attacker could trick Redis interpretation of dense HLL encoding to write up to 3 bytes beyond the end of a heap-allocated buffer.

Vendors
redislabsredhatdebiancanonicaloracle
Products
redis, openstack, software collections, enterprise linux, enterprise linux eus, enterprise linux server aus, enterprise linux server tus, debian linux, ubuntu linux, communications operations monitor
Weakness
CWE-122, CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.