CVE-2018-11219
Description
An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2, leading to a failure of bounds checking.
In plain language
AI Worth attentionCVE-2018-11219 is a Redis flaw in its Lua scripting feature that lets an unauthenticated person on the network crash Redis or potentially take it over; if you run an affected Redis version, you should act.
CVE-2018-11219 is an unauthenticated remote integer-overflow in the Redis Lua subsystem (struct library) that breaks bounds checking, enabling memory out-of-bounds access that can lead to denial of service or arbitrary code execution; fixed in Redis 3.2.12, 4.0.10, and 5.0 RC2.
What to do now
- Check your Redis version and whether the Lua scripting subsystem is enabled.
- If you are on Redis 3.2.11 or older, 4.0.9 or older, or 5.0 up to RC1, plan an upgrade now.
- Upgrade Redis to at least 3.2.12, 4.0.10, or 5.0 RC2 (whichever matches your supported branch).
- After upgrading, verify the running Redis version and that the vulnerable build is no longer deployed.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-11219 and every CVE in our database. Create a free account — no credit card required.
Create Free Account