Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mrcw-fhw9-fj8j

Опубликовано: 20 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

Integer overflow in the Redis SETRANGE and SORT/SORT_RO commands may result with false OOM panic

Impact

Authenticated users issuing specially crafted SETRANGE and SORT(_RO) commands can trigger an integer overflow, resulting with Redis attempting to allocate impossible amounts of memory and abort with an OOM panic.

Patches

The problem is fixed in Redis versions 7.0.8, 6.2.9 and 6.0.17.

Credit

The issue has been identified by Xion (SeungHyun Lee) of KAIST GoN

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

redis

redis
Затронутые версииВерсия исправления

>=6.0.0, <6.0.17

6.0.17

Наименование

redis

redis
Затронутые версииВерсия исправления

>=6.2.0, <6.2.9

6.2.9

Наименование

redis

redis
Затронутые версииВерсия исправления

>=7.0.0, <7.0.8

7.0.8

EPSS

Процентиль: 98%
0.37299
Средний

5.5 Medium

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 3 лет назад

Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SETRANGE` and `SORT(_RO)` commands can trigger an integer overflow, resulting with Redis attempting to allocate impossible amounts of memory and abort with an out-of-memory (OOM) panic. The problem is fixed in Redis versions 7.0.8, 6.2.9 and 6.0.17. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 5.5
redhat
больше 3 лет назад

Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SETRANGE` and `SORT(_RO)` commands can trigger an integer overflow, resulting with Redis attempting to allocate impossible amounts of memory and abort with an out-of-memory (OOM) panic. The problem is fixed in Redis versions 7.0.8, 6.2.9 and 6.0.17. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 5.5
nvd
больше 3 лет назад

Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SETRANGE` and `SORT(_RO)` commands can trigger an integer overflow, resulting with Redis attempting to allocate impossible amounts of memory and abort with an out-of-memory (OOM) panic. The problem is fixed in Redis versions 7.0.8, 6.2.9 and 6.0.17. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 5.5
msrc
больше 3 лет назад

Integer overflow in certain command arguments can drive Redis to OOM panic

CVSS3: 5.5
debian
больше 3 лет назад

Redis is an in-memory database that persists on disk. Authenticated us ...

EPSS

Процентиль: 98%
0.37299
Средний

5.5 Medium

CVSS3

Дефекты

CWE-190