Логотип exploitDog
bind:CVE-2022-24736
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-24736

Количество 12

Количество 12

ubuntu логотип

CVE-2022-24736

больше 3 лет назад

Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. The problem is fixed in Redis versions 7.0.0 and 6.2.7. An additional workaround to mitigate this problem without patching the redis-server executable, if Lua scripting is not being used, is to block access to `SCRIPT LOAD` and `EVAL` commands using ACL rules.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2022-24736

больше 3 лет назад

Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. The problem is fixed in Redis versions 7.0.0 and 6.2.7. An additional workaround to mitigate this problem without patching the redis-server executable, if Lua scripting is not being used, is to block access to `SCRIPT LOAD` and `EVAL` commands using ACL rules.

CVSS3: 3.3
EPSS: Низкий
nvd логотип

CVE-2022-24736

больше 3 лет назад

Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. The problem is fixed in Redis versions 7.0.0 and 6.2.7. An additional workaround to mitigate this problem without patching the redis-server executable, if Lua scripting is not being used, is to block access to `SCRIPT LOAD` and `EVAL` commands using ACL rules.

CVSS3: 3.3
EPSS: Низкий
msrc логотип

CVE-2022-24736

больше 3 лет назад

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2022-24736

больше 3 лет назад

Redis is an in-memory database that persists on disk. Prior to version ...

CVSS3: 3.3
EPSS: Низкий
fstec логотип

BDU:2022-02940

больше 3 лет назад

Уязвимость системы управления базами данных Redis, связанная с ошибками разыменования указателей, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 3.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1929-1

около 3 лет назад

Security update for redis

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1842-1

около 3 лет назад

Security update for redis

EPSS: Низкий
rocky логотип

RLSA-2022:8096

больше 2 лет назад

Low: redis security and bug fix update

EPSS: Низкий
rocky логотип

RLSA-2022:7541

почти 3 года назад

Low: redis:6 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2022-8096

больше 2 лет назад

ELSA-2022-8096: redis security and bug fix update (LOW)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-7541

больше 2 лет назад

ELSA-2022-7541: redis:6 security, bug fix, and enhancement update (LOW)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-24736

Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. The problem is fixed in Redis versions 7.0.0 and 6.2.7. An additional workaround to mitigate this problem without patching the redis-server executable, if Lua scripting is not being used, is to block access to `SCRIPT LOAD` and `EVAL` commands using ACL rules.

CVSS3: 3.3
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-24736

Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. The problem is fixed in Redis versions 7.0.0 and 6.2.7. An additional workaround to mitigate this problem without patching the redis-server executable, if Lua scripting is not being used, is to block access to `SCRIPT LOAD` and `EVAL` commands using ACL rules.

CVSS3: 3.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-24736

Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. The problem is fixed in Redis versions 7.0.0 and 6.2.7. An additional workaround to mitigate this problem without patching the redis-server executable, if Lua scripting is not being used, is to block access to `SCRIPT LOAD` and `EVAL` commands using ACL rules.

CVSS3: 3.3
0%
Низкий
больше 3 лет назад
msrc логотип
CVSS3: 5.5
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-24736

Redis is an in-memory database that persists on disk. Prior to version ...

CVSS3: 3.3
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2022-02940

Уязвимость системы управления базами данных Redis, связанная с ошибками разыменования указателей, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 3.3
0%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1929-1

Security update for redis

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1842-1

Security update for redis

около 3 лет назад
rocky логотип
RLSA-2022:8096

Low: redis security and bug fix update

больше 2 лет назад
rocky логотип
RLSA-2022:7541

Low: redis:6 security, bug fix, and enhancement update

почти 3 года назад
oracle-oval логотип
ELSA-2022-8096

ELSA-2022-8096: redis security and bug fix update (LOW)

больше 2 лет назад
oracle-oval логотип
ELSA-2022-7541

ELSA-2022-7541: redis:6 security, bug fix, and enhancement update (LOW)

больше 2 лет назад

Уязвимостей на страницу