Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-3647

Опубликовано: 21 окт. 2022
Источник: redhat
CVSS3: 2.3
EPSS Низкий

Описание

** DISPUTED ** A vulnerability, which was classified as problematic, was found in Redis up to 6.2.7/7.0.5. Affected is the function sigsegvHandler of the file debug.c of the component Crash Report. The manipulation leads to denial of service. The complexity of an attack is rather high. The exploitability is told to be difficult. The real existence of this vulnerability is still doubted at the moment. Upgrading to version 6.2.8 and 7.0.6 is able to address this issue. The patch is identified as 0bf90d944313919eb8e63d3588bf63a367f020a3. It is recommended to apply a patch to fix this issue. VDB-211962 is the identifier assigned to this vulnerability. NOTE: The vendor claims that this is not a DoS because it applies to the crash logging mechanism which is triggered after a crash has occurred.

A flaw was found in Redis when calling the sigsegvHandler function of the debug component crash report. This issue causes a crash, ignoring the report information and kills the processes, which leads to a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 2redisAffected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/redisgraph-tls-rhel8Fix deferred
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/search-api-rhel8Fix deferred
Red Hat Ansible Tower 3redisAffected
Red Hat Enterprise Linux 8redis:5/redisWill not fix
Red Hat Enterprise Linux 8redis:6/redisFix deferred
Red Hat Enterprise Linux 9redisFix deferred
Red Hat Fuse 7io.hawt-hawtio-integrationWill not fix
Red Hat OpenStack Platform 13 (Queens)openstack-13Out of support scope
Red Hat Software Collectionsrh-redis5-redisWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-404
https://bugzilla.redhat.com/show_bug.cgi?id=2137209redis: crash in sigsegvHandler debug function

EPSS

Процентиль: 22%
0.0007
Низкий

2.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.1
ubuntu
больше 2 лет назад

** DISPUTED ** A vulnerability, which was classified as problematic, was found in Redis up to 6.2.7/7.0.5. Affected is the function sigsegvHandler of the file debug.c of the component Crash Report. The manipulation leads to denial of service. The complexity of an attack is rather high. The exploitability is told to be difficult. The real existence of this vulnerability is still doubted at the moment. Upgrading to version 6.2.8 and 7.0.6 is able to address this issue. The patch is identified as 0bf90d944313919eb8e63d3588bf63a367f020a3. It is recommended to apply a patch to fix this issue. VDB-211962 is the identifier assigned to this vulnerability. NOTE: The vendor claims that this is not a DoS because it applies to the crash logging mechanism which is triggered after a crash has occurred.

CVSS3: 3.1
nvd
больше 2 лет назад

** DISPUTED ** A vulnerability, which was classified as problematic, was found in Redis up to 6.2.7/7.0.5. Affected is the function sigsegvHandler of the file debug.c of the component Crash Report. The manipulation leads to denial of service. The complexity of an attack is rather high. The exploitability is told to be difficult. The real existence of this vulnerability is still doubted at the moment. Upgrading to version 6.2.8 and 7.0.6 is able to address this issue. The patch is identified as 0bf90d944313919eb8e63d3588bf63a367f020a3. It is recommended to apply a patch to fix this issue. VDB-211962 is the identifier assigned to this vulnerability. NOTE: The vendor claims that this is not a DoS because it applies to the crash logging mechanism which is triggered after a crash has occurred.

CVSS3: 3.3
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 3.1
debian
больше 2 лет назад

** DISPUTED ** A vulnerability, which was classified as problematic, w ...

suse-cvrf
больше 2 лет назад

Security update for redis

EPSS

Процентиль: 22%
0.0007
Низкий

2.3 Low

CVSS3