Vulnerability Name: | CVE-2022-35977 (CCN-245141) | ||||||||||||
Assigned: | 2022-07-15 | ||||||||||||
Published: | 2023-01-20 | ||||||||||||
Updated: | 2023-02-02 | ||||||||||||
Summary: | Redis is vulnerable to a denial of service, caused by an integer overflow flaw. By sending specially-crafted SETRANGE and SORT(_RO) commands, a local authenticated attacker could exploit this vulnerability to allocate impossible amounts of memory and abort with an OOM panic. | ||||||||||||
CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) 4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:C)
| ||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-35977 Source: XF Type: UNKNOWN redis-cve202235977-dos(245141) Source: security-advisories@github.com Type: Patch, Third Party Advisory security-advisories@github.com Source: security-advisories@github.com Type: Release Notes, Third Party Advisory security-advisories@github.com Source: security-advisories@github.com Type: Release Notes, Third Party Advisory security-advisories@github.com Source: security-advisories@github.com Type: Release Notes, Third Party Advisory security-advisories@github.com Source: CCN Type: Redis GIT Repository Integer overflow in the Redis SETRANGE and SORT/SORT_RO commands may result with false OOM panic Source: security-advisories@github.com Type: Third Party Advisory security-advisories@github.com Source: CCN Type: IBM Security Bulletin 6999327 (Qradar Advisor) IBM QRadar Advisor With Watson App for IBM QRadar SIEM is vulnerable to using components with known vulnerabilities Source: CCN Type: IBM Security Bulletin 7011697 (Storage Protect Plus Container Agent) Vulnerabilities in Python, OpenSSH, Golang Go, Minio and Redis may affect IBM Spectrum Protect Plus Container backup and restore for Kubernetes and OpenShift Source: CCN Type: Mend Vulnerability Database CVE-2022-35977 | ||||||||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||||||||
BACK |