Executive Summary

Informations
Name CVE-2021-32761 First vendor Publication 2021-07-21
Vendor Cve Last vendor Modification 2024-11-21

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Overall CVSS Score 7.5
Base Score 7.5 Environmental Score 7.5
impact SubScore 5.9 Temporal Score 7.5
Exploitabality Sub Score 1.6
 
Attack Vector Network Attack Complexity High
Privileges Required Low User Interaction None
Scope Unchanged Confidentiality Impact High
Integrity Impact High Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:S/C:P/I:P/A:P)
Cvss Base Score 6 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity Medium
Cvss Expoit Score 6.8 Authentication Requires single instance
Calculate full CVSS 2.0 Vectors scores

Detail

Redis is an in-memory database that persists on disk. A vulnerability involving out-of-bounds read and integer overflow to buffer overflow exists starting with version 2.2 and prior to versions 5.0.13, 6.0.15, and 6.2.5. On 32-bit systems, Redis `*BIT*` command are vulnerable to integer overflow that can potentially be exploited to corrupt the heap, leak arbitrary heap contents or trigger remote code execution. The vulnerability involves changing the default `proto-max-bulk-len` configuration parameter to a very large value and constructing specially crafted commands bit commands. This problem only affects Redis on 32-bit platforms, or compiled as a 32-bit binary. Redis versions 5.0.`3m 6.0.15, and 6.2.5 contain patches for this issue. An additional workaround to mitigate the problem without patching the `redis-server` executable is to prevent users from modifying the `proto-max-bulk-len` configuration parameter. This can be done using ACL to restrict unprivileged users from using the CONFIG SET command.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32761

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 20
Os 3
Os 2

Sources (Detail)

https://github.com/redis/redis/security/advisories/GHSA-8wxq-j7rp-g8wj
https://lists.debian.org/debian-lts-announce/2021/07/msg00017.html
https://lists.debian.org/debian-lts-announce/2021/08/msg00026.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedora...
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedora...
https://security.gentoo.org/glsa/202209-17
https://security.netapp.com/advisory/ntap-20210827-0004/
https://www.debian.org/security/2021/dsa-5001
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
Date Informations
2024-11-28 13:56:56
  • Multiple Updates
2024-08-02 13:25:27
  • Multiple Updates
2024-08-02 01:25:40
  • Multiple Updates
2024-02-02 02:25:40
  • Multiple Updates
2024-02-01 12:23:57
  • Multiple Updates
2023-11-07 21:34:27
  • Multiple Updates
2023-09-05 13:19:58
  • Multiple Updates
2023-09-05 01:23:29
  • Multiple Updates
2023-09-02 13:18:34
  • Multiple Updates
2023-09-02 01:23:50
  • Multiple Updates
2023-08-12 13:24:41
  • Multiple Updates
2023-08-12 01:23:04
  • Multiple Updates
2023-08-11 13:16:57
  • Multiple Updates
2023-08-11 01:23:50
  • Multiple Updates
2023-08-06 13:14:56
  • Multiple Updates
2023-08-06 01:22:49
  • Multiple Updates
2023-08-04 13:15:18
  • Multiple Updates
2023-08-04 01:23:10
  • Multiple Updates
2023-07-14 13:15:22
  • Multiple Updates
2023-07-14 01:22:58
  • Multiple Updates
2023-03-29 02:17:32
  • Multiple Updates
2023-03-28 12:23:11
  • Multiple Updates
2022-10-11 05:27:41
  • Multiple Updates
2022-10-11 01:22:40
  • Multiple Updates
2022-10-06 21:27:37
  • Multiple Updates
2022-09-29 21:27:37
  • Multiple Updates
2022-07-03 00:27:30
  • Multiple Updates
2021-11-29 05:23:07
  • Multiple Updates
2021-11-18 05:23:11
  • Multiple Updates
2021-11-10 09:23:29
  • Multiple Updates
2021-11-06 13:23:09
  • Multiple Updates
2021-09-29 00:23:15
  • Multiple Updates
2021-09-22 00:23:09
  • Multiple Updates
2021-08-27 21:23:35
  • Multiple Updates
2021-08-27 13:23:04
  • Multiple Updates
2021-08-04 21:23:15
  • Multiple Updates
2021-08-01 12:42:44
  • Multiple Updates
2021-07-30 21:23:11
  • Multiple Updates
2021-07-28 01:43:08
  • Multiple Updates
2021-07-28 01:42:56
  • Multiple Updates
2021-07-27 17:22:49
  • Multiple Updates
2021-07-22 17:22:48
  • Multiple Updates
2021-07-22 05:22:49
  • First insertion