Описание
A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent. An out of bounds write vulnerability exists in the handling of the client-output-buffer-limit option during the CONFIG SET command for the Redis data structure store. A crafted CONFIG SET command can lead to an out of bounds write potentially resulting in code execution.
Отчет
No currently supported version of Red Hat OpenStack Platform or Red Hat Enterprise Linux OpenStack Platform is affected by this flaw.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) | redis | Not affected | ||
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | redis | Not affected | ||
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational Tools | redis | Not affected | ||
| Red Hat Mobile Application Platform On-Premise 4.1.0 | redis | Not affected | ||
| Red Hat OpenStack Platform 10 (Newton) | redis | Not affected | ||
| Red Hat OpenStack Platform 10 (Newton) Operational Tools | redis | Not affected | ||
| Red Hat OpenStack Platform 8 (Liberty) | redis | Not affected | ||
| Red Hat OpenStack Platform 8 (Liberty) Operational Tools | redis | Not affected | ||
| Red Hat OpenStack Platform 9 (Mitaka) | redis | Not affected | ||
| Red Hat OpenStack Platform 9 (Mitaka) Operational Tools | redis | Not affected |
Показывать по
Дополнительная информация
Статус:
6.6 Medium
CVSS3
4.6 Medium
CVSS2
Связанные уязвимости
A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent. An out of bounds write vulnerability exists in the handling of the client-output-buffer-limit option during the CONFIG SET command for the Redis data structure store. A crafted CONFIG SET command can lead to an out of bounds write potentially resulting in code execution.
A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent. An out of bounds write vulnerability exists in the handling of the client-output-buffer-limit option during the CONFIG SET command for the Redis data structure store. A crafted CONFIG SET command can lead to an out of bounds write potentially resulting in code execution.
A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code ...
A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent. An out of bounds write vulnerability exists in the handling of the client-output-buffer-limit option during the CONFIG SET command for the Redis data structure store. A crafted CONFIG SET command can lead to an out of bounds write potentially resulting in code execution.
6.6 Medium
CVSS3
4.6 Medium
CVSS2