Lucene search

K
freebsdFreeBSD96B2D4DB-DDD2-11ED-B6EA-080027F5FEC9
HistoryApr 17, 2023 - 12:00 a.m.

redis -- HINCRBYFLOAT can be used to crash a redis-server process

2023-04-1700:00:00
vuxml.freebsd.org
12
redis
hincrbyfloat
vulnerability
hash field
crash
unix

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

0.002 Low

EPSS

Percentile

53.5%

Redis core team reports:

    Authenticated users can use the HINCRBYFLOAT command to
    create an invalid hash field that may later crash Redis on
    access.
OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchredis< 7.0.11UNKNOWN
FreeBSDanynoarchredis62< 6.2.12UNKNOWN
FreeBSDanynoarchredis6< 6.0.19UNKNOWN

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

0.002 Low

EPSS

Percentile

53.5%