Red Hat Bugzilla – Bug 1590062
CVE-2018-11219 redis: Integer overflow in lua_struct.c:b_unpack()
Last modified: 2018-09-23 22:56:34 EDT
Redis is vulnerable to an integer overflow in the lua_struct.c:b_unpack() function. A remote attacker could exploit this to cause a denial of service or have other unspecified impact.
External References: http://antirez.com/news/119
Created redis tracking bugs for this issue: Affects: epel-all [bug 1591538] Affects: fedora-all [bug 1591540]
Acknowledgments: (none)
We already have 4.0.10
Patches: https://github.com/antirez/redis/commit/1eb08bcd4634ae42ec45e8284923ac048beaa4c3 https://github.com/antirez/redis/commit/e89086e09a38cc6713bcd4b9c29abf92cf393936