ZeroHour

CVE-2023-41056

CVSS 3.1
8.1 high
EPSS
3%p84
Published
()
Modified
Description

Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4.

Vendors
redisfedoraproject
Products
redis, fedora
Weakness
CWE-190, CWE-762
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.