VDB

CVE-2020-14147

CVE-2020-14147 PUBLISHED CVSS 7.699999809265137 HIGH

An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly bypass intended sandbox restrictions via a large number, which triggers a stack-based buffer overflow. NOTE: this issue exists because of a CVE-2015-8080 regression.

EPSS 3.09% · 86.9th percentile

Risk Scores

CVSS 3.1
7.699999809265137
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
EPSS Score
3.09%
86.9th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:20.04:LTSredis5:5.0.5-2build1, 5:5.0.6-1, 5:5.0.7-1

Timeline

  • Jun 15, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Dec 28, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Jul 4, 2022 EPSS Score
  • Sep 6, 2022 EPSS Score
  • Nov 7, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›