vendor:
Redis
by:
Fakhri Zulkifli
8.4
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Redis
Affected Version From: 3.2
Affected Version To: 5
Patch Exists: YES
Related CWE: CVE-2018-12326
CPE: a:redis:redis
Platforms Tested:
2018
Redis-cli < 5.0 - Buffer Overflow (PoC)
Buffer overflow in redis-cli of Redis version 3.2, 4.0, and 5.0 allows a local attacker to achieve code execution and escalate to higher privileges via a long string in the hostname parameter.
Mitigation:
Upgrade to fixed version