CVE-2018-11218

Related Vulnerabilities: CVE-2018-11218  

Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows.

The MITRE CVE dictionary describes this issue as:

Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows.

Find out more about CVE-2018-11218 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

CVSS3 Base Score 6.3
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity Impact Low
Availability Impact Low

Red Hat Security Errata

Platform Errata Release Date
Red Hat OpenStack Platform 13.0 (Queens) (redis) RHSA-2019:0094 2019-01-16
Red Hat OpenStack Platform 10 (redis) RHSA-2019:0052 2019-01-16

Affected Packages State

Platform Package State
Red Hat Software Collections for Red Hat Enterprise Linux rh-redis32-redis Affected
Red Hat OpenStack Platform Operational Tools 9 redis Affected
Red Hat OpenStack Platform 9.0 redis Affected
Red Hat OpenStack Platform 8.0 (Liberty) redis Affected
Red Hat OpenStack Platform 12.0 redis Affected
Red Hat Mobile Application Platform On-Premise 4 rhmap-redis-docker Affected
Red Hat JBoss Fuse 7 camel-spring-redis Not affected
Red Hat JBoss Fuse 6 camel-spring-redis Not affected
Red Hat Enterprise Linux OpenStack Platform 8.0 Operational Tools for RHEL 7 redis Affected
Red Hat Enterprise Linux OpenStack Platform 7.0 Operational Tools for RHEL 7 redis Will not fix
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 redis Will not fix

External References