← All CVEs

CVE-2019-10192

high · 7.2

A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By carefully corrupting a hyperloglog using the SETRANGE command, an attacker could trick Redis interpretation of dense HLL encoding to write up to 3 bytes beyond the end of a heap-allocated buffer.

7.2
CVSS
26.0%
EPSS (exploit prob.)
98th
EPSS percentile
2019-07-11
Published

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-122CWE-787

Affected products

VendorProductAffected versions
redislabsredis>= 3.0.0, < 3.2.13
redislabsredis>= 4.0.0, < 4.0.14
redislabsredis>= 5.0, < 5.0.4
redhatopenstack9
redhatopenstack10
redhatopenstack13
redhatopenstack14
redhatsoftware_collections1.0
redhatenterprise_linux8.0
redhatenterprise_linux_eus8.1
redhatenterprise_linux_eus8.2
redhatenterprise_linux_eus8.4
redhatenterprise_linux_server_aus8.2
redhatenterprise_linux_server_aus8.4
redhatenterprise_linux_server_tus8.2
redhatenterprise_linux_server_tus8.4
debiandebian_linux9.0
debiandebian_linux10.0
canonicalubuntu_linux16.04
canonicalubuntu_linux18.04
canonicalubuntu_linux19.04
oraclecommunications_operations_monitor3.4
oraclecommunications_operations_monitor4.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-10192