Lucene search

K
freebsdFreeBSDF1F637D1-39EB-11ED-AB44-080027F5FEC9
HistorySep 21, 2022 - 12:00 a.m.

redis -- Potential remote code execution vulnerability

2022-09-2100:00:00
vuxml.freebsd.org
83
redis
remote code execution
vulnerability
integer overflow
heap overflow
xautoclaim command

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.029 Low

EPSS

Percentile

90.8%

The Redis core team reports:

    Executing a XAUTOCLAIM command on a stream key in a
    specific state, with a specially crafted COUNT argument,
    may cause an integer overflow, a subsequent heap overflow,
    and potentially lead to remote code execution. The problem
    affects Redis versions 7.0.0 or newer.
OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchredis= 7.0.0UNKNOWN
FreeBSDanynoarchredis< 7.0.5UNKNOWN

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.029 Low

EPSS

Percentile

90.8%