Index: security/vuxml/vuln-2021.xml =================================================================== --- security/vuxml/vuln-2021.xml +++ security/vuxml/vuln-2021.xml @@ -1,3 +1,85 @@ + + redis -- multiple vulnerabilities + + + redis + 6.2.6 + + + redis6 + 6.0.16 + + + redis5 + 5.0.14 + + + + +

The Redis Team reports:

+
+
+
CVE-2021-41099
+
+ Integer to heap buffer overflow handling certain string commands + and network payloads, when proto-max-bulk-len is manually configured. +
+
CVE-2021-32762
+
+ Integer to heap buffer overflow issue in redis-cli and redis-sentinel + parsing large multi-bulk replies on some older and less common platforms. +
+
CVE-2021-32687
+
+ Integer to heap buffer overflow with intsets, when set-max-intset-entries + is manually configured to a non-default, very large value. +
+
CVE-2021-32675
+
+ Denial Of Service when processing RESP request payloads with a large + number of elements on many connections. +
+
CVE-2021-32672
+
+ Random heap reading issue with Lua Debugger. +
+
CVE-2021-32628
+
+ Integer to heap buffer overflow handling ziplist-encoded data types, + when configuring a large, non-default value for hash-max-ziplist-entries, + hash-max-ziplist-value, zset-max-ziplist-entries or zset-max-ziplist-value. +
+
CVE-2021-32627
+
+ Integer to heap buffer overflow issue with streams, when configuring + a non-default, large value for proto-max-bulk-len and + client-query-buffer-limit. +
+
CVE-2021-32626
+
+ Specially crafted Lua scripts may result with Heap buffer overflow. +
+
+
+ +
+ + CVE-2021-41099 + CVE-2021-32762 + CVE-2021-32687 + CVE-2021-32675 + CVE-2021-32672 + CVE-2021-32628 + CVE-2021-32627 + CVE-2021-32626 + https://groups.google.com/g/redis-db/c/GS_9L2KCk9g + + + 2021-10-04 + 2021-10-05 + +
+ Apache httpd -- Multiple vulnerabilities