Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-25155

Опубликовано: 02 мар. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.5

Описание

Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted SRANDMEMBER, ZRANDMEMBER, and HRANDFIELD commands can trigger an integer overflow, resulting in a runtime assertion and termination of the Redis server process. This problem affects all Redis versions. Patches were released in Redis version(s) 6.0.18, 6.2.11 and 7.0.9.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

5:7.0.15-1build2
esm-apps/bionic

released

5:4.0.9-1ubuntu0.2+esm4
esm-apps/focal

released

5:5.0.7-2ubuntu0.1+esm2
esm-apps/jammy

released

5:6.0.16-1ubuntu1+esm1
esm-apps/noble

not-affected

5:7.0.12-1
esm-apps/xenial

released

2:3.0.6-1ubuntu0.4+esm2
esm-infra-legacy/trusty

not-affected

2:2.8.4-2ubuntu0.2+esm3
focal

ignored

end of standard support, was needed
jammy

needed

Показывать по

EPSS

Процентиль: 86%
0.0296
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
больше 2 лет назад

Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SRANDMEMBER`, `ZRANDMEMBER`, and `HRANDFIELD` commands can trigger an integer overflow, resulting in a runtime assertion and termination of the Redis server process. This problem affects all Redis versions. Patches were released in Redis version(s) 6.0.18, 6.2.11 and 7.0.9.

CVSS3: 5.5
nvd
больше 2 лет назад

Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SRANDMEMBER`, `ZRANDMEMBER`, and `HRANDFIELD` commands can trigger an integer overflow, resulting in a runtime assertion and termination of the Redis server process. This problem affects all Redis versions. Patches were released in Redis version(s) 6.0.18, 6.2.11 and 7.0.9.

CVSS3: 6.5
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 5.5
debian
больше 2 лет назад

Redis is an in-memory database that persists on disk. Authenticated us ...

CVSS3: 6.5
redos
больше 2 лет назад

Уязвимость Redis

EPSS

Процентиль: 86%
0.0296
Низкий

5.5 Medium

CVSS3

Уязвимость CVE-2023-25155