CVE-2015-8080: Buffer Overflow
Integer overflow in the getnum function in luastruct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly bypass intended sandbox restrictions via a large number, which triggers a stack-based buffer overflow.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8080?
CVE-2015-8080 has a high severity due to its potential for denial of service and memory corruption.
How do I fix CVE-2015-8080?
To fix CVE-2015-8080, upgrade Redis to version 2.8.24 or 3.0.6 or later.
What versions of Redis are affected by CVE-2015-8080?
CVE-2015-8080 affects Redis versions before 2.8.24 and 3.0.6.
Can CVE-2015-8080 allow bypassing the Redis sandbox?
Yes, CVE-2015-8080 may potentially allow attackers to bypass the intended Redis sandbox.
What impact does CVE-2015-8080 have on systems running Redis?
CVE-2015-8080 can lead to application crashes and possible exploitation of systems running vulnerable Redis versions.