Back

HIGH

redis: Code execution in redis-cli via crafted command line arguments

Published Jun 17, 2018

Description

Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to higher privileges via a crafted command line. NOTE: It is unclear whether there are any common situations in which redis-cli is used with, for example, a -h (aka hostname) argument from an untrusted source.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 17, 2018
Updated Aug 5, 2024
Reserved Jun 13, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jun 13, 2018