Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-31449

Опубликовано: 07 окт. 2024
Источник: ubuntu
Приоритет: high
EPSS Низкий
CVSS3: 7

Описание

Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack buffer overflow in the bit library, which may potentially lead to remote code execution. The problem exists in all versions of Redis with Lua scripting. This problem has been fixed in Redis versions 6.2.16, 7.2.6, and 7.4.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

РелизСтатусПримечание
devel

needed

esm-apps-legacy/xenial

needed

esm-apps/bionic

needed

esm-apps/focal

released

1.0.2-5ubuntu0.20.04.1~esm2
esm-apps/jammy

released

1.0.2-5ubuntu0.22.04.1~esm2
esm-apps/noble

needed

esm-apps/resolute

needed

esm-apps/xenial

ignored

end of ESM support, was needed
jammy

needed

noble

needed

Показывать по

РелизСтатусПримечание
devel

not-affected

code not present
esm-apps-legacy/xenial

released

2:3.0.6-1ubuntu0.4+esm5
esm-apps/bionic

released

5:4.0.9-1ubuntu0.2+esm7
esm-apps/focal

not-affected

5:5.0.7-2ubuntu0.1+esm4
esm-apps/jammy

not-affected

5:6.0.16-1ubuntu1.1+esm1
esm-apps/noble

released

5:7.0.15-1ubuntu0.24.04.4
esm-apps/resolute

not-affected

code not present
esm-apps/xenial

released

2:3.0.6-1ubuntu0.4+esm5
esm-infra-legacy/trusty

not-affected

2:2.8.4-2ubuntu0.2+esm5
focal

ignored

end of standard support, was needs-triage

Показывать по

EPSS

Процентиль: 91%
0.04495
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7
redhat
почти 2 года назад

Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack buffer overflow in the bit library, which may potentially lead to remote code execution. The problem exists in all versions of Redis with Lua scripting. This problem has been fixed in Redis versions 6.2.16, 7.2.6, and 7.4.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 7
nvd
почти 2 года назад

Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack buffer overflow in the bit library, which may potentially lead to remote code execution. The problem exists in all versions of Redis with Lua scripting. This problem has been fixed in Redis versions 6.2.16, 7.2.6, and 7.4.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 7
msrc
больше 1 года назад

Lua library commands may lead to stack overflow and RCE in Redis

CVSS3: 7
debian
почти 2 года назад

Redis is an open source, in-memory database that persists on disk. An ...

CVSS3: 7
github
почти 2 года назад

Lua library commands may lead to stack overflow and potential RCE

EPSS

Процентиль: 91%
0.04495
Низкий

7 High

CVSS3