Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3470

Опубликовано: 26 окт. 2020
Источник: redhat
CVSS3: 5.3

Описание

A heap overflow issue was found in Redis in versions before 5.0.10, before 6.0.9 and before 6.2.0 when using a heap allocator other than jemalloc or glibc's malloc, leading to potential out of bound write or process crash. Effectively this flaw does not affect the vast majority of users, who use jemalloc or glibc malloc.

A heap overflow issue was found in Redis when using a heap allocator other than jemalloc or glibc's malloc, leading to potential out of bound write or process crash. Effectively this flaw does not affect the vast majority of users, who use jemalloc or glibc.

Отчет

The following products are not affected by this flaw because they use jemalloc as default heap allocator:

  • Red Hat Enterprise Linux 8
  • Red Hat Software Collections
  • Red Hat Advanced Cluster Management for Kubernetes In Red Hat OpenStack Platform, because the flaw has a lower impact and the fix would require a substantial amount of development, no update will be provided at this time for the RHOSP redis package.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2redisgraph-tlsNot affected
Red Hat Advanced Cluster Management for Kubernetes 2search-apiNot affected
Red Hat Ansible Automation Platform 1.2redisNot affected
Red Hat Ansible Tower 3redisNot affected
Red Hat Enterprise Linux 8redis:5/redisNot affected
Red Hat Enterprise Linux 8redis:6/redisNot affected
Red Hat Enterprise Linux 9redisNot affected
Red Hat OpenStack Platform 10 (Newton)redisWill not fix
Red Hat OpenStack Platform 13 (Queens)redisWill not fix
Red Hat Software Collectionsrh-redis5-redisNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1943623redis: potential heap overflow when using a heap allocator other than jemalloc or glibc's malloc

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 5 лет назад

A heap overflow issue was found in Redis in versions before 5.0.10, before 6.0.9 and before 6.2.0 when using a heap allocator other than jemalloc or glibc's malloc, leading to potential out of bound write or process crash. Effectively this flaw does not affect the vast majority of users, who use jemalloc or glibc malloc.

CVSS3: 5.3
nvd
почти 5 лет назад

A heap overflow issue was found in Redis in versions before 5.0.10, before 6.0.9 and before 6.2.0 when using a heap allocator other than jemalloc or glibc's malloc, leading to potential out of bound write or process crash. Effectively this flaw does not affect the vast majority of users, who use jemalloc or glibc malloc.

CVSS3: 5.3
msrc
почти 5 лет назад

Описание отсутствует

CVSS3: 5.3
debian
почти 5 лет назад

A heap overflow issue was found in Redis in versions before 5.0.10, be ...

github
больше 3 лет назад

A heap overflow issue was found in Redis in versions before 5.0.10, before 6.0.9 and before 6.2.0 when using a heap allocator other than jemalloc or glibc's malloc, leading to potential out of bound write or process crash. Effectively this flaw does not affect the vast majority of users, who use jemalloc or glibc malloc.

5.3 Medium

CVSS3