VDB
CVE-2018-11219
CVE-2018-11219
PUBLISHED
CVSS 9.800000190734863 CRITICAL
An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2, leading to a failure of bounds checking.
EPSS 6.97% · 93.7th percentile
Risk Scores
CVSS 3.0
9.800000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
6.97%
93.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:18.04:LTS | redis | 5:4.0.6-2, *, 5:4.0.9-1 |
| Ubuntu:16.04:LTS | redis | *, 0, 2:3.0.5-2 |
| Ubuntu:14.04:LTS | redis | *, 2:2.8.4-2, 2:2.8.2-1 |
Timeline
- Jun 17, 2018 CVE Published
- Apr 14, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Mar 1, 2022 EPSS Score
- Jul 4, 2022 EPSS Score
- Nov 8, 2022 EPSS Score
- Jan 9, 2023 EPSS Score
- Mar 13, 2023 EPSS Score
- May 15, 2023 EPSS Score
- Jul 16, 2023 EPSS Score
- Sep 17, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2018-11219 third-party-advisory
- https://github.com/antirez/redis/issues/5017 third-party-advisory
- http://antirez.com/news/119 third-party-advisory
- https://github.com/antirez/redis/commit/1eb08bcd4634ae42ec45e8284923ac048beaa4c3 third-party-advisory
- https://github.com/antirez/redis/commit/e89086e09a38cc6713bcd4b9c29abf92cf393936 third-party-advisory
- https://raw.githubusercontent.com/antirez/redis/4.0/00-RELEASENOTES third-party-advisory
- https://raw.githubusercontent.com/antirez/redis/5.0/00-RELEASENOTES third-party-advisory
- https://www.debian.org/security/2018/dsa-4230 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2018-11219 third-party-advisory