CVE-2018-11218
40Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 74%
from disclosure to weapon149 days
Published on NVDJun 17
metasploit+149d
exploitation probability
74%top 1% of all CVEs
observed exploitation
nono source reports it
Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows.
Affected products
n/a · n/aReferences
http://antirez.com/news/119https://access.redhat.com/errata/RHSA-2019:0052https://access.redhat.com/errata/RHSA-2019:0094https://access.redhat.com/errata/RHSA-2019:1860https://github.com/antirez/redis/commit/52a00201fca331217c3b4b8b634f6a0f57d6b7d3https://github.com/antirez/redis/commit/5ccb6f7a791bf3490357b00a898885759d98bab0https://github.com/antirez/redis/issues/5017https://raw.githubusercontent.com/antirez/redis/4.0/00-RELEASENOTEShttps://raw.githubusercontent.com/antirez/redis/5.0/00-RELEASENOTEShttps://security.gentoo.org/glsa/201908-04https://www.debian.org/security/2018/dsa-4230https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html