• A
    Security: update Lua struct package for security. · 8783fb94
    antirez 提交于
    During an auditing Apple found that the "struct" Lua package
    we ship with Redis (http://www.inf.puc-rio.br/~roberto/struct/) contains
    a security problem. A bound-checking statement fails because of integer
    overflow. The bug exists since we initially integrated this package with
    Lua, when scripting was introduced, so every version of Redis with
    EVAL/EVALSHA capabilities exposed is affected.
    Instead of just fixing the bug, the library was updated to the latest
    version shipped by the author.
lua_struct.c 10.9 KB