7.2
CVSSv3

CVE-2019-10192

Published: 11/07/2019 Updated: 28/10/2021
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x prior to 3.2.13, 4.x prior to 4.0.14 and 5.x prior to 5.0.4. By carefully corrupting a hyperloglog using the SETRANGE command, an attacker could trick Redis interpretation of dense HLL encoding to write up to 3 bytes beyond the end of a heap-allocated buffer.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redislabs redis

redhat openstack 9

redhat openstack 10

redhat openstack 13

redhat openstack 14

redhat software collections 1.0

redhat enterprise linux 8.0

redhat enterprise linux eus 8.1

redhat enterprise linux eus 8.2

redhat enterprise linux eus 8.4

redhat enterprise linux server aus 8.2

redhat enterprise linux server aus 8.4

redhat enterprise linux server tus 8.2

redhat enterprise linux server tus 8.4

debian debian linux 9.0

debian debian linux 10.0

canonical ubuntu linux 19.04

canonical ubuntu linux 18.04

canonical ubuntu linux 16.04

oracle communications operations monitor 3.4

oracle communications operations monitor 4.1

Vendor Advisories

Debian Bug report logs - #931625 redis: CVE-2019-10192 CVE-2019-10193 Package: redis; Maintainer for redis is Chris Lamb <lamby@debianorg>; Source for redis is src:redis (PTS, buildd, popcon) Reported by: "Chris Lamb" <lamby@debianorg> Date: Mon, 8 Jul 2019 12:36:02 UTC Severity: grave Tags: security Found in ve ...
Several security issues were fixed in Redis ...
Multiple vulnerabilities were discovered in the HyperLogLog implementation of Redis, a persistent key-value database, which could result in denial of service or potentially the execution of arbitrary code For the oldstable distribution (stretch), these problems have been fixed in version 3:326-3+deb9u3 For the stable distribution (buster), thes ...
Synopsis Important: redis security update Type/Severity Security Advisory: Important Topic An update for redis is now available for Red Hat OpenStack Platform 140 (Rocky)Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) ba ...
Synopsis Important: redis:5 security update Type/Severity Security Advisory: Important Topic An update for the redis:5 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) ...
Synopsis Important: rh-redis5-redis security update Type/Severity Security Advisory: Important Topic An update for rh-redis5-redis is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System ...
Synopsis Important: redis security update Type/Severity Security Advisory: Important Topic An update for redis is now available for Red Hat OpenStack Platform 90 (Mitaka)Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) ba ...
Synopsis Important: redis security update Type/Severity Security Advisory: Important Topic An update for redis is now available for Red Hat OpenStack Platform 100 (Newton)Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) b ...
Synopsis Important: redis security update Type/Severity Security Advisory: Important Topic An update for redis is now available for Red Hat OpenStack Platform 90 Operational Tools for RHEL 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scor ...
Synopsis Important: rh-redis32-redis security update Type/Severity Security Advisory: Important Topic An update for rh-redis32-redis is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring Syste ...
Synopsis Important: redis security update Type/Severity Security Advisory: Important Topic An update for redis is now available for Red Hat OpenStack Platform 130 (Queens)Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) b ...