Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5gc4-76rx-22c9

Опубликовано: 22 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

Heap overflow in Redis 7.0 XAUTOCLAIM command's COUNT argument.

Impact

Executing a XAUTOCLAIM command on a stream key in a specific state, with a specially crafted COUNT argument may cause an integer overflow, a subsequent heap overflow, and potentially lead to remote code execution. The problem affects Redis versions 7.0.0 or newer.

Patches

The problem is fixed in Redis version 7.0.5.

Credits

This problem was identified by Xion (SeungHyun Lee) of KAIST GoN.

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

redis

redis
Затронутые версииВерсия исправления

>= 7.0.0

7.0.5

EPSS

Процентиль: 86%
0.03013
Низкий

7 High

CVSS3

Дефекты

CWE-680

Связанные уязвимости

CVSS3: 7
ubuntu
почти 4 года назад

Redis is an in-memory database that persists on disk. Versions 7.0.0 and above, prior to 7.0.5 are vulnerable to an Integer Overflow. Executing an `XAUTOCLAIM` command on a stream key in a specific state, with a specially crafted `COUNT` argument may cause an integer overflow, a subsequent heap overflow, and potentially lead to remote code execution. This has been patched in Redis version 7.0.5. No known workarounds exist.

CVSS3: 9.8
redhat
почти 4 года назад

Redis is an in-memory database that persists on disk. Versions 7.0.0 and above, prior to 7.0.5 are vulnerable to an Integer Overflow. Executing an `XAUTOCLAIM` command on a stream key in a specific state, with a specially crafted `COUNT` argument may cause an integer overflow, a subsequent heap overflow, and potentially lead to remote code execution. This has been patched in Redis version 7.0.5. No known workarounds exist.

CVSS3: 7
nvd
почти 4 года назад

Redis is an in-memory database that persists on disk. Versions 7.0.0 and above, prior to 7.0.5 are vulnerable to an Integer Overflow. Executing an `XAUTOCLAIM` command on a stream key in a specific state, with a specially crafted `COUNT` argument may cause an integer overflow, a subsequent heap overflow, and potentially lead to remote code execution. This has been patched in Redis version 7.0.5. No known workarounds exist.

CVSS3: 7
debian
почти 4 года назад

Redis is an in-memory database that persists on disk. Versions 7.0.0 a ...

CVSS3: 7
fstec
почти 4 года назад

Уязвимость реализации команды XAUTOCLAIM системы управления базами данных (СУБД) Redis, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 86%
0.03013
Низкий

7 High

CVSS3

Дефекты

CWE-680