4.3
CVE-2021-32672
- EPSS 1.83%
- Veröffentlicht 04.10.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:30
- Erkennungen
Vulnerability in Lua Debugger in Redis
Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send malformed requests that cause the debugger’s protocol parser to read data beyond the actual buffer. This issue affects all versions of Redis with Lua debugging support (3.2 or newer). The problem is fixed in versions 6.2.6, 6.0.16 and 5.0.14.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Software Collections Version -
Redhat ≫ Enterprise Linux Version 8.0
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
Fedoraproject ≫ Fedora Version 33
Fedoraproject ≫ Fedora Version 34
Fedoraproject ≫ Fedora Version 35
Netapp ≫ Management Services For Element Software Version -
Netapp ≫ Management Services For Netapp Hci Version -
Oracle ≫ Communications Operations Monitor Version 4.3
Oracle ≫ Communications Operations Monitor Version 4.4
Oracle ≫ Communications Operations Monitor Version 5.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.83% | 0.767 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| NIST | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
| security-advisories@github.com | 5.3 | 1.6 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
https://www.oracle.com/security-alerts/cpuapr2022.html
https://security.gentoo.org/glsa/202209-17
https://www.debian.org/security/2021/dsa-5001
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HTYQ5ZF37HNGTZWVNJD3VXP7I6MEEF42/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VL5KXFN3ATM7IIM7Q4O4PWTSRGZ5744Z/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WR5WKJWXD4D6S3DJCZ56V74ESLTDQRAB/
https://security.netapp.com/advisory/ntap-20211104-0003/
https://github.com/redis/redis/commit/6ac3c0b7abd35f37201ed2d6298ecef4ea1ae1dd
https://github.com/redis/redis/security/advisories/GHSA-9mj9-xx53-qmxm