[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250039

 
 

909

 
 

195882

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2REDIS6-2023-001 --- redis

ID: oval:org.secpod.oval:def:1701680Date: (C)2023-10-26   (M)2024-04-17
Class: PATCHFamily: unix




Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SETRANGE` and `SORT` commands can trigger an integer overflow, resulting with Redis attempting to allocate impossible amounts of memory and abort with an out-of-memory panic. The problem is fixed in Redis versions 7.0.8, 6.2.9 and 6.0.17. Users are advised to upgrade. There are no known workarounds for this vulnerability. Redis is an in-memory database that persists on disk. Authenticated users can use string matching commands with a specially crafted pattern to trigger a denial-of-service attack on Redis, causing it to hang and consume 100% CPU time. The problem is fixed in Redis versions 6.0.18, 6.2.11, 7.0.9. Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` command with specially crafted arguments to trigger a denial-of-service by crashing Redis with an assertion failure. This problem affects Redis versions 6.2 or newer up to but not including 6.2.9 as well as versions 7.0 up to but not including 7.0.8. Users are advised to upgrade. There are no known workarounds for this vulnerability. Redis is an in-memory database that persists on disk. Authenticated users issuing specially crafted `SRANDMEMBER`, `ZRANDMEMBER`, and `HRANDFIELD` commands can trigger an integer overflow, resulting in a runtime assertion and termination of the Redis server process. This problem affects all Redis versions. Patches were released in Redis version 6.0.18, 6.2.11 and 7.0.9

Platform:
Amazon Linux 2
Product:
redis
Reference:
ALAS2REDIS6-2023-001
CVE-2022-35977
CVE-2022-36021
CVE-2023-22458
CVE-2023-25155
CVE    4
CVE-2022-35977
CVE-2023-22458
CVE-2023-25155
CVE-2022-36021
...
CPE    2
cpe:/a:redis:redis
cpe:/o:amazon:linux:2

© SecPod Technologies