VYPR
High severity8.4OSV Advisory· Published Jun 17, 2018· Updated Jun 17, 2026

CVE-2018-12326

CVE-2018-12326

Description

Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to higher privileges via a crafted command line. NOTE: It is unclear whether there are any common situations in which redis-cli is used with, for example, a -h (aka hostname) argument from an untrusted source.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Range: 1.3.6, 2.2-alpha0, 2.2-alpha1, …
  • Redis/Redis4 versions
    cpe:2.3:a:redislabs:redis:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:redislabs:redis:*:*:*:*:*:*:*:*range: <4.0.10
    • cpe:2.3:a:redislabs:redis:5.0:rc1:*:*:*:*:*:*
    • cpe:2.3:a:redislabs:redis:5.0:rc2:*:*:*:*:*:*
    • (no CPE)range: <4.0.10, <5.0 RC3

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.