Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38955
HistoryJan 22, 2023 - 8:13 a.m.

Denial Of Service (DoS)

2023-01-2208:13:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
redis
dos
vulnerability
integer overflow
memory allocation
oom panic
authenticated users
setrange
sort
commands

0.0004 Low

EPSS

Percentile

14.2%

redis is vulnerable to Denial of Service(DoS) attacks. Authenticated users issuing specially crafted SETRANGE and SORT(_RO) commands can trigger an integer overflow, resulting with the library attempting to allocate impossible amounts of memory and abort with an out-of-memory (OOM) panic.