CVE-2019-10193
A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 23.7%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By corrupting a hyperloglog using the SETRANGE command, an attacker could cause Redis to perform controlled increments of up to 12 bytes past the end of a stack-allocated buffer.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 23.70% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-121, CWE-787
- Affected
- redislabs/redis · redhat/openstack · redhat/enterprise linux · redhat/enterprise linux eus · redhat/enterprise linux server aus · redhat/enterprise linux server tus · debian/debian linux · canonical/ubuntu linux · oracle/communications operations monitor
- Source
- secalert@redhat.com
References
- http://www.securityfocus.com/bid/109290Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:1819Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2002Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10193Issue Tracking, Third Party Advisory
- https://raw.githubusercontent.com/antirez/redis/3.2/00-RELEASENOTESRelease Notes, Vendor Advisory
- https://raw.githubusercontent.com/antirez/redis/4.0/00-RELEASENOTESRelease Notes, Vendor Advisory
- https://raw.githubusercontent.com/antirez/redis/5.0/00-RELEASENOTESRelease Notes, Vendor Advisory
- https://seclists.org/bugtraq/2019/Jul/19Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/201908-04Third Party Advisory
- https://usn.ubuntu.com/4061-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4480Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/109290Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:1819Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2002Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10193Issue Tracking, Third Party Advisory
- https://raw.githubusercontent.com/antirez/redis/3.2/00-RELEASENOTESRelease Notes, Vendor Advisory
- https://raw.githubusercontent.com/antirez/redis/4.0/00-RELEASENOTESRelease Notes, Vendor Advisory
- https://raw.githubusercontent.com/antirez/redis/5.0/00-RELEASENOTESRelease Notes, Vendor Advisory
- https://seclists.org/bugtraq/2019/Jul/19Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/201908-04Third Party Advisory
- https://usn.ubuntu.com/4061-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4480Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.htmlPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.