[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2021-32762Date: (C)2021-10-05   (M)2023-12-22


Redis is an open source, in-memory database that persists on disk. The redis-cli command line tool and redis-sentinel service may be vulnerable to integer overflow when parsing specially crafted large multi-bulk network replies. This is a result of a vulnerability in the underlying hiredis library which does not perform an overflow check before calling the calloc() heap allocation function. This issue only impacts systems with heap allocators that do not perform their own overflow checks. Most modern systems do and are therefore not likely to be affected. Furthermore, by default redis-sentinel uses the jemalloc allocator which is also not vulnerable. The problem is fixed in Redis versions 6.2.6, 6.0.16 and 5.0.14.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 8.8CVSS Score : 9.0
Exploit Score: 2.8Exploit Score: 8.0
Impact Score: 5.9Impact Score: 10.0
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: LOWAuthentication: SINGLE
User Interaction: NONEConfidentiality: COMPLETE
Scope: UNCHANGEDIntegrity: COMPLETE
Confidentiality: HIGHAvailability: COMPLETE
Integrity: HIGH 
Availability: HIGH 
  
Reference:
DSA-5001
FEDORA-2021-61c487f241
FEDORA-2021-8913c7900c
FEDORA-2021-aa94492a09
GLSA-202209-17
https://github.com/redis/redis/commit/0215324a66af949be39b34be2d55143232c1cb71
https://github.com/redis/redis/security/advisories/GHSA-833w-8v3m-8wwr
https://security.netapp.com/advisory/ntap-20211104-0003/
https://www.oracle.com/security-alerts/cpuapr2022.html

CPE    1
cpe:/a:redis:redis
CWE    1
CWE-190
OVAL    6
oval:org.secpod.oval:def:120872
oval:org.secpod.oval:def:120870
oval:org.secpod.oval:def:1701716
oval:org.secpod.oval:def:76355
...

© SecPod Technologies