Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20916
HistoryJul 29, 2019 - 12:08 a.m.

Arbitrary Code Execution

2019-07-2900:08:36
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18

EPSS

0.152

Percentile

95.9%

redis is vulnerable to arbitrary code execution. A heap-based buffer overflow with corrupted hyperloglog data structure allows an attacker to execute arbitrary code by carefully corrupting a hyperloglog structure using the SETRANGE command to trick the interpretation of dense HLL encoding to write up to 3 bytes beyond the end of a heap-allocated buffer.