Candidate: CVE-2015-8080 PublicDate: 2016-04-13 15:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8080 https://github.com/antirez/redis/issues/2855 Description: Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly bypass intended sandbox restrictions via a large number, which triggers a stack-based buffer overflow. Ubuntu-Description: It was discovered that Redis incorrectly handled large number inputs. An attacker could possibly use this issue to case a denial of service or bypass sandbox restrictions. Notes: leosilva> code already patched in xenial Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=804419 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_redis: upstream_redis: released (2:2.8.17-1+deb8u3, 2:3.0.6-4) precise_redis: ignored (reached end-of-life) precise/esm_redis: DNE (precise was needs-triage) trusty_redis: released (2:2.8.4-2ubuntu0.2) trusty/esm_redis: released (2:2.8.4-2ubuntu0.2) vivid_redis: ignored (reached end-of-life) vivid/stable-phone-overlay_redis: DNE vivid/ubuntu-core_redis: DNE wily_redis: ignored (reached end-of-life) xenial_redis: not-affected (2:3.0.6-1) yakkety_redis: ignored (reached end-of-life) zesty_redis: ignored (reached end-of-life) artful_redis: ignored (reached end-of-life) bionic_redis: not-affected (5:4.0.9-1) devel_redis: not-affected (5:4.0.11-2)