Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-27151

Опубликовано: 29 мая 2025
Источник: nvd
CVSS3: 4.7
CVSS3: 9.8
EPSS Низкий

Описание

Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exists in redis-check-aof due to the use of memcpy with strlen(filepath) when copying a user-supplied file path into a fixed-size stack buffer. This allows an attacker to overflow the stack and potentially achieve code execution. This issue has been patched in version 8.0.2.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*
Версия от 7.0.0 (включая) до 7.4.4 (исключая)
cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*
Версия от 8.0.0 (включая) до 8.0.2 (исключая)

EPSS

Процентиль: 24%
0.00078
Низкий

4.7 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 4.7
ubuntu
5 месяцев назад

Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exists in redis-check-aof due to the use of memcpy with strlen(filepath) when copying a user-supplied file path into a fixed-size stack buffer. This allows an attacker to overflow the stack and potentially achieve code execution. This issue has been patched in version 8.0.2.

CVSS3: 2.5
redhat
5 месяцев назад

Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exists in redis-check-aof due to the use of memcpy with strlen(filepath) when copying a user-supplied file path into a fixed-size stack buffer. This allows an attacker to overflow the stack and potentially achieve code execution. This issue has been patched in version 8.0.2.

CVSS3: 4.7
msrc
4 месяца назад

redis-check-aof may lead to stack overflow and potential RCE

CVSS3: 4.7
debian
5 месяцев назад

Redis is an open source, in-memory database that persists on disk. In ...

suse-cvrf
4 месяца назад

Security update for redis

EPSS

Процентиль: 24%
0.00078
Низкий

4.7 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-20