• 公告ID (KylinSec-SA-2023-1034)

摘要:

Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` command with specially crafted arguments to trigger a denial-of-service by crashing Redis with an assertion failure. This problem affects Redis versions 6.2 or newer up to but not including 6.2.9 as well as versions 7.0 up to but not including 7.0.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.

安全等级: Low

公告ID: KylinSec-SA-2023-1034

发布日期: 2023年2月6日

关联CVE: CVE-2023-22458  

  • 详细介绍

1. 漏洞描述

   

Redis is an in-memory database that persists on disk. Authenticated users can issue a `HRANDFIELD` or `ZRANDMEMBER` command with specially crafted arguments to trigger a denial-of-service by crashing Redis with an assertion failure. This problem affects Redis versions 6.2 or newer up to but not including 6.2.9 as well as versions 7.0 up to but not including 7.0.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2023-22458 KY3.4-4A redis Unaffected
CVE-2023-22458 KY3.4-5 redis Unaffected
CVE-2023-22458 KY3.5.1 redis Unaffected
CVE-2023-22458 KY3.5.2 redis Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2023-1033 下一篇:KylinSec-SA-2023-1035