APP: Lua Subsystem Redis CVE-2018-11219 Integer Overflow

This signature detects attempts to exploit a known vulnerability against Lua Subsystem Redis. A successful attack can result in a denial-of-service condition.

Extended Description

An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2, leading to a failure of bounds checking.

Affected Products

Redhat openstack

Short Name
APP:REDIS-STRUCT-IO
Severity
Major
Recommended
True
Recommended Action
Drop
Category
APP
Keywords
CVE-2018-11219 Integer Lua Overflow Redis Subsystem
Release Date
07/23/2018
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
Port
TCP/6379
False Positive
Unknown
Vendors

Oracle

Redislabs

Debian

Redhat

CVSS Score

7.5

Found a potential security threat?