Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:31303
HistoryJul 23, 2021 - 11:39 p.m.

Remote Code Execution

2021-07-2323:39:15
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
vulnerability
buffer overflow
attacker
configuration parameter
crafted commands
software

EPSS

0.017

Percentile

87.9%

redis is vulnerable to remote code execution. An out-of-bounds read and integer overflow to buffer overflow exists and allows an attacker to execute arbitrary code on the host OS by changing the default proto-max-bulk-len configuration parameter to a very large value and constructing specially crafted commands bit commands.