Lucene search

K
freebsdFreeBSDA60CC0E4-C7AA-11ED-8A4B-080027F5FEC9
HistoryMar 20, 2023 - 12:00 a.m.

redis -- specially crafted MSETNX command can lead to denial-of-service

2023-03-2000:00:00
vuxml.freebsd.org
11
redis
msetnx
denial of service
vulnerability
runtime assertion
termination
server
unix

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

5.1%

Yupeng Yang reports:

    Authenticated users can use the MSETNX command to trigger
    a runtime assertion and termination of the Redis server
    process.
OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchredis< 7.0.10UNKNOWN
FreeBSDanynoarchredis-devel< 7.0.10.20230320UNKNOWN

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

5.1%