CVE-2018-12326 PUBLISHED

Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to higher privileges via a crafted command line. NOTE: It is unclear whether there are any common situations in which redis-cli is used with, for example, a -h (aka hostname) argument from an untrusted source.

EPSS 28.11% · 96.4th percentile

Risk Scores

EPSS Score
28.11%
96.4th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSredis0, 2:2.6.13-1, 2:2.6.16-3
Ubuntu:18.04:LTSredis5:4.0.9-1, 4:4.0.2-9, 5:4.0.5-1
Ubuntu:16.04:LTSredis2:3.0.3-3, 2:3.0.5-1, 2:3.0.5-2

Timeline

References

Open in Interactive Console →