Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows.
[
{
"id": "CVE-2018-11218-700a840d",
"signature_type": "Line",
"digest": {
"line_hashes": [
"16911033430593959714276436254180720746",
"118647126258626533724160258916734123784",
"266997613451356111695635551196073534977"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/antirez/redis/commit/52a00201fca331217c3b4b8b634f6a0f57d6b7d3",
"target": {
"file": "deps/lua/src/lua_cmsgpack.c"
}
},
{
"id": "CVE-2018-11218-d30d5814",
"signature_type": "Function",
"digest": {
"length": 471.0,
"function_hash": "311114601621233800883377513176254974414"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/antirez/redis/commit/52a00201fca331217c3b4b8b634f6a0f57d6b7d3",
"target": {
"function": "mp_pack",
"file": "deps/lua/src/lua_cmsgpack.c"
}
}
]