Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r8w2-2m53-gprj

Опубликовано: 20 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

Integer overflow in the Redis HRANDFIELD and ZRANDMEMBER commands may lead to denial-of-service

Impact

Authenticated users can issue a HRANDFIELD or ZRANDMEMBER command with specially crafted arguments to trigger a denial-of-service by crashing Redis with an assertion.

This problem affects Redis 6.2 or newer.

Patches

The problem is fixed in Redis versions 6.2.9 and 7.0.8.

Credit

This issue has been identified and reported by yype on GitHub.

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

redis

redis
Затронутые версииВерсия исправления

>=6.2.0, <6.2.9

6.2.9

Наименование

redis

redis
Затронутые версииВерсия исправления

>=7.0.0, <7.0.8

7.0.8

EPSS

Процентиль: 99%
0.71984
Высокий

5.5 Medium

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 3 лет назад

Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` command with specially crafted arguments to trigger a denial-of-service by crashing Redis with an assertion failure. This problem affects Redis versions 6.2 or newer up to but not including 6.2.9 as well as versions 7.0 up to but not including 7.0.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 5.5
redhat
больше 3 лет назад

Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` command with specially crafted arguments to trigger a denial-of-service by crashing Redis with an assertion failure. This problem affects Redis versions 6.2 or newer up to but not including 6.2.9 as well as versions 7.0 up to but not including 7.0.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 5.5
nvd
больше 3 лет назад

Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` command with specially crafted arguments to trigger a denial-of-service by crashing Redis with an assertion failure. This problem affects Redis versions 6.2 or newer up to but not including 6.2.9 as well as versions 7.0 up to but not including 7.0.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 5.5
msrc
больше 3 лет назад

Integer overflow in multiple Redis commands can lead to denial-of-service

CVSS3: 5.5
debian
больше 3 лет назад

Redis is an in-memory database that persists on disk. Authenticated us ...

EPSS

Процентиль: 99%
0.71984
Высокий

5.5 Medium

CVSS3

Дефекты

CWE-190