---
cve: "CVE-2018-12326"
severity: "LOW"
cvss: 3.1
epss: "2.7%"
vendor: "n/a"
kev: false
exploited: false
published: "2018-06-17 14:29:00"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T19:45:45+02:00"
---

# CVE-2018-12326

> 3.1 LOW · 🧪 PoC

## Beschreibung

Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to higher privileges via a crafted command line. NOTE: It is unclear whether there are any common situations in which redis-cli is used with, for example, a -h (aka hostname) argument from an untrusted source.

## Exploit-Evidenz

- [EDB-44904 — Redis-cli < 5.0 - Buffer Overflow (PoC)](https://www.exploit-db.com/exploits/44904)

## Patch verfügbar (OSV)

- 9fdcc15962f9ff4baebe6fdd947816f43f730d50 (Commit)
- 556b2d2bee22d1307e696090c9be10fc10a47cd3 (Commit)

## Referenzen

- <https://gist.github.com/fakhrizulkifli/f831f40ec6cde4f744c552503d8698f0>
- <https://www.exploit-db.com/exploits/44904/>
- <https://access.redhat.com/errata/RHSA-2019:0052>
- <https://access.redhat.com/errata/RHSA-2019:0094>
- <https://github.com/antirez/redis/commit/9fdcc15962f9ff4baebe6fdd947816f43f730d50>
- <https://raw.githubusercontent.com/antirez/redis/4.0/00-RELEASENOTES>
- <https://raw.githubusercontent.com/antirez/redis/5.0/00-RELEASENOTES>
- <https://access.redhat.com/errata/RHSA-2019:1860>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2018-12326) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
