CVE-2018-12326
Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to higher privileges via a crafted command line.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.68%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to higher privileges via a crafted command line. NOTE: It is unclear whether there are any common situations in which redis-cli is used with, for example, a -h (aka hostname) argument from an untrusted source.
- CVSS 3.0
- 8.4 HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.68% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- redislabs/redis
- Source
- cve@mitre.org
References
- https://access.redhat.com/errata/RHSA-2019:0052
- https://access.redhat.com/errata/RHSA-2019:0094
- https://access.redhat.com/errata/RHSA-2019:1860
- https://gist.github.com/fakhrizulkifli/f831f40ec6cde4f744c552503d8698f0Third Party Advisory
- https://github.com/antirez/redis/commit/9fdcc15962f9ff4baebe6fdd947816f43f730d50Patch, Third Party Advisory
- https://raw.githubusercontent.com/antirez/redis/4.0/00-RELEASENOTESPatch, Third Party Advisory
- https://raw.githubusercontent.com/antirez/redis/5.0/00-RELEASENOTESPatch, Third Party Advisory
- https://www.exploit-db.com/exploits/44904/Exploit, Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:0052
- https://access.redhat.com/errata/RHSA-2019:0094
- https://access.redhat.com/errata/RHSA-2019:1860
- https://gist.github.com/fakhrizulkifli/f831f40ec6cde4f744c552503d8698f0Third Party Advisory
- https://github.com/antirez/redis/commit/9fdcc15962f9ff4baebe6fdd947816f43f730d50Patch, Third Party Advisory
- https://raw.githubusercontent.com/antirez/redis/4.0/00-RELEASENOTESPatch, Third Party Advisory
- https://raw.githubusercontent.com/antirez/redis/5.0/00-RELEASENOTESPatch, Third Party Advisory
- https://www.exploit-db.com/exploits/44904/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.