Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-31144

Опубликовано: 19 июл. 2022
Источник: debian

Описание

Redis is an in-memory database that persists on disk. A specially crafted `XAUTOCLAIM` command on a stream key in a specific state may result with heap overflow, and potentially remote code execution. This problem affects versions on the 7.x branch prior to 7.0.4. The patch is released in version 7.0.4.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
redisfixed5:7.0.4-1package
redisnot-affectedbullseyepackage
redisnot-affectedbusterpackage

Примечания

  • https://github.com/redis/redis/security/advisories/GHSA-96f7-42fg-2jrh

  • https://github.com/redis/redis/commit/15ae4e29e537e7ec37f0df1825d9fb2beea67124

Связанные уязвимости

CVSS3: 7
ubuntu
больше 3 лет назад

Redis is an in-memory database that persists on disk. A specially crafted `XAUTOCLAIM` command on a stream key in a specific state may result with heap overflow, and potentially remote code execution. This problem affects versions on the 7.x branch prior to 7.0.4. The patch is released in version 7.0.4.

CVSS3: 7
redhat
больше 3 лет назад

Redis is an in-memory database that persists on disk. A specially crafted `XAUTOCLAIM` command on a stream key in a specific state may result with heap overflow, and potentially remote code execution. This problem affects versions on the 7.x branch prior to 7.0.4. The patch is released in version 7.0.4.

CVSS3: 7
nvd
больше 3 лет назад

Redis is an in-memory database that persists on disk. A specially crafted `XAUTOCLAIM` command on a stream key in a specific state may result with heap overflow, and potentially remote code execution. This problem affects versions on the 7.x branch prior to 7.0.4. The patch is released in version 7.0.4.

CVSS3: 7
msrc
4 месяца назад

Potential heap overflow in Redis

CVSS3: 7
fstec
больше 3 лет назад

Уязвимость системы управления базами данных (СУБД) Redis, связанная с переполнением буфера в куче, позволяющая нарушителю выполнить произвольный код