CVE-2020-14147
An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.08%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly bypass intended sandbox restrictions via a large number, which triggers a stack-based buffer overflow. NOTE: this issue exists because of a CVE-2015-8080 regression.
- CVSS 3.1
- 7.7 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
- EPSS
- 3.08% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190, CWE-787
- Affected
- redislabs/redis · oracle/communications operations monitor · suse/linux enterprise · debian/debian linux
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00058.htmlMailing List, Third Party Advisory
- https://github.com/antirez/redis/commit/ef764dde1cca2f25d00686673d1bc89448819571Patch, Third Party Advisory
- https://github.com/antirez/redis/pull/6875Patch, Third Party Advisory
- https://security.gentoo.org/glsa/202008-17Third Party Advisory
- https://www.debian.org/security/2020/dsa-4731Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00058.htmlMailing List, Third Party Advisory
- https://github.com/antirez/redis/commit/ef764dde1cca2f25d00686673d1bc89448819571Patch, Third Party Advisory
- https://github.com/antirez/redis/pull/6875Patch, Third Party Advisory
- https://security.gentoo.org/glsa/202008-17Third Party Advisory
- https://www.debian.org/security/2020/dsa-4731Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.