Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3qpw-7686-5984

Опубликовано: 27 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 3.3

Описание

A Malformed Lua script can crash Redis

Impact

An attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. This issue affects all versions of Redis.

Patches

The problem is fixed in Redis versions 7.0.0 and 6.2.7.

Workarounds

An additional workaround to mitigate this problem without patching the redis-server executable, if Lua scripting is not being used, is to block access to SCRIPT LOAD and EVAL commands using ACL rules.

Credit

This problem has been reported by Aviv Yahav.

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

redis

redis
Затронутые версииВерсия исправления

>=6.2.0, <6.2.7

6.2.7

EPSS

Процентиль: 71%
0.01498
Низкий

3.3 Low

CVSS3

Дефекты

CWE-476

Связанные уязвимости

CVSS3: 3.3
ubuntu
больше 4 лет назад

Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. The problem is fixed in Redis versions 7.0.0 and 6.2.7. An additional workaround to mitigate this problem without patching the redis-server executable, if Lua scripting is not being used, is to block access to `SCRIPT LOAD` and `EVAL` commands using ACL rules.

CVSS3: 3.3
redhat
больше 4 лет назад

Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. The problem is fixed in Redis versions 7.0.0 and 6.2.7. An additional workaround to mitigate this problem without patching the redis-server executable, if Lua scripting is not being used, is to block access to `SCRIPT LOAD` and `EVAL` commands using ACL rules.

CVSS3: 3.3
nvd
больше 4 лет назад

Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. The problem is fixed in Redis versions 7.0.0 and 6.2.7. An additional workaround to mitigate this problem without patching the redis-server executable, if Lua scripting is not being used, is to block access to `SCRIPT LOAD` and `EVAL` commands using ACL rules.

CVSS3: 5.5
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 3.3
debian
больше 4 лет назад

Redis is an in-memory database that persists on disk. Prior to version ...

EPSS

Процентиль: 71%
0.01498
Низкий

3.3 Low

CVSS3

Дефекты

CWE-476