Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-3470


A heap overflow issue was found in Redis in versions before 5.0.10, before 6.0.9 and before 6.2.0 when using a heap allocator other than jemalloc or glibc's malloc, leading to potential out of bound write or process crash. Effectively this flaw does not affect the vast majority of users, who use jemalloc or glibc malloc.


Published

2021-03-31T14:15:20.937

Last Modified

2024-11-21T06:21:37.290

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-119
  • Type: Primary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application redislabs redis < 5.0.10 Yes
Application redislabs redis < 6.0.9 Yes
Application redislabs redis 6.2.0 Yes
Application redislabs redis 6.2.0 Yes
Application redislabs redis 6.2.0 Yes

References