CVE Database
/

CVE-2015-8080

Back to search

CVE-2015-8080

Published: Apr 13, 2016

Modified: Aug 6, 2024

PUBLISHED

Description

Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly bypass intended sandbox restrictions via a large number, which triggers a stack-based buffer overflow.

VendorProductVersions

n/a

n/a

affected
n/a

References

openSUSE-SU-2016:1444
vendor-advisory
x_refsource_SUSE
RHSA-2016:0097
vendor-advisory
x_refsource_REDHAT
DSA-3412
vendor-advisory
x_refsource_DEBIAN
RHSA-2016:0095
vendor-advisory
x_refsource_REDHAT
77507
vdb-entry
x_refsource_BID
RHSA-2016:0096
vendor-advisory
x_refsource_REDHAT
GLSA-201702-16
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now