CVE-2015-4335
Publication date 9 June 2015
Last updated 24 July 2024
Ubuntu priority
Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.
From the Ubuntu Security Team
It was discovered that Redis incorrectly handled eval commands. An attacker could possibly use this issue to execute arbitrary code.
Status
Package | Ubuntu Release | Status |
---|---|---|
redis | 18.04 LTS bionic |
Not affected
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Fixed 2:2.8.4-2ubuntu0.2
|
|