CVE-2018-11218
30Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 59%
from disclosure to weapon149 days
Published on NVDJun 17
metasploit+149d
exploitation probability
59%top 1% of all CVEs
observed exploitation
nono source reports it
Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows.
Affected products
n/a · n/aReferences
http://antirez.com/news/119https://access.redhat.com/errata/RHSA-2019:0052https://access.redhat.com/errata/RHSA-2019:0094https://access.redhat.com/errata/RHSA-2019:1860https://github.com/antirez/redis/commit/52a00201fca331217c3b4b8b634f6a0f57d6b7d3https://github.com/antirez/redis/commit/5ccb6f7a791bf3490357b00a898885759d98bab0https://github.com/antirez/redis/issues/5017https://raw.githubusercontent.com/antirez/redis/4.0/00-RELEASENOTEShttps://raw.githubusercontent.com/antirez/redis/5.0/00-RELEASENOTEShttps://security.gentoo.org/glsa/201908-04https://www.debian.org/security/2018/dsa-4230https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html