Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-41056


Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue has been patched in version 7.0.15 and 7.2.4.


Published

2024-01-10T16:15:46.557

Last Modified

2024-11-21T08:20:28.383

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

Weaknesses
  • Type: Primary
    CWE-190
    CWE-762

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application redis redis < 7.0.15 Yes
Application redis redis < 7.2.4 Yes
Operating System fedoraproject fedora 38 Yes
Operating System fedoraproject fedora 39 Yes

References