Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9mj9-xx53-qmxm

Опубликовано: 04 окт. 2021
Источник: github
Github: Не прошло ревью
CVSS3: 3.1

Описание

Vulnerability in Lua Debugger

Impact

When using the Redis Lua Debugger, users can send malformed requests that cause the debugger’s protocol parser to read data beyond the actual buffer. This issue affects all versions of Redis with Lua debugging support (3.2 or newer).

Patches

The problem is fixed in versions 6.2.6, 6.0.16 and 5.0.14.

Credit

This problem was found by Meir Shpilraien.

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

redis

redis
Затронутые версииВерсия исправления

>=5.0.0, <5.0.14

5.0.14

Наименование

redis

redis
Затронутые версииВерсия исправления

>=6.0.0, <6.0.16

6.0.16

Наименование

redis

redis
Затронутые версииВерсия исправления

>=6.2.0, <6.2.6

6.2.6

EPSS

Процентиль: 77%
0.01831
Низкий

3.1 Low

CVSS3

Дефекты

CWE-125
CWE-126

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 5 лет назад

Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send malformed requests that cause the debugger’s protocol parser to read data beyond the actual buffer. This issue affects all versions of Redis with Lua debugging support (3.2 or newer). The problem is fixed in versions 6.2.6, 6.0.16 and 5.0.14.

CVSS3: 3.1
redhat
почти 5 лет назад

Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send malformed requests that cause the debugger’s protocol parser to read data beyond the actual buffer. This issue affects all versions of Redis with Lua debugging support (3.2 or newer). The problem is fixed in versions 6.2.6, 6.0.16 and 5.0.14.

CVSS3: 5.3
nvd
почти 5 лет назад

Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send malformed requests that cause the debugger’s protocol parser to read data beyond the actual buffer. This issue affects all versions of Redis with Lua debugging support (3.2 or newer). The problem is fixed in versions 6.2.6, 6.0.16 and 5.0.14.

CVSS3: 4.3
msrc
почти 5 лет назад

Vulnerability in Lua Debugger in Redis

CVSS3: 5.3
debian
почти 5 лет назад

Redis is an open source, in-memory database that persists on disk. Whe ...

EPSS

Процентиль: 77%
0.01831
Низкий

3.1 Low

CVSS3

Дефекты

CWE-125
CWE-126