Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-41056

Опубликовано: 09 янв. 2024
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4.

A flaw was found in Redis. When processing a certain sequence of payloads, Redis may incorrectly handle the resizing of memory buffers, leading to a heap-based buffer overflow, potentially resulting in a denial of service or remote code execution.

Отчет

The redis package, as shipped with Red Hat Enterprise Linux 8, 9, and RHSCL is not affected by this vulnerability because the vulnerable code was introduced in a newer version of redis. However, the redis:7 module as shipped with Red Hat Enterprise Linux 9.3 is affected.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 23scale-amp-backend-containerNot affected
Red Hat 3scale API Management Platform 23scale-amp-system-containerNot affected
Red Hat Ansible Automation Platform 1.2ansible-towerOut of support scope
Red Hat Enterprise Linux 8redis:6/redisNot affected
Red Hat Enterprise Linux 9redisNot affected
Red Hat Fuse 7redisNot affected
Red Hat Quay 3quay/quay-rhel8Affected
Red Hat Software Collectionsrh-redis6-redisNot affected
Red Hat Enterprise Linux 9redisFixedRHEA-2024:114305.03.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2257454redis: Heap Buffer Overflow may lead to potential remote code execution

EPSS

Процентиль: 89%
0.05119
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 1 года назад

Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4.

CVSS3: 8.1
nvd
больше 1 года назад

Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4.

CVSS3: 8.1
debian
больше 1 года назад

Redis is an in-memory database that persists on disk. Redis incorrectl ...

CVSS3: 8.1
fstec
больше 1 года назад

Уязвимость системы управления базами данных (СУБД) Redis, связанная с целочисленным переполнением, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.1
redos
около 1 года назад

Уязвимость redis

EPSS

Процентиль: 89%
0.05119
Низкий

8.1 High

CVSS3