漏洞信息详情
Hiredis 输入验证错误漏洞
漏洞简介
Hiredis是一款用于Redis数据库的C语言客户端。
Hiredis 存在安全漏洞,该漏洞允许攻击者提供恶意制作或损坏的RESP、mult-bulk 协议数据,可导致整数溢出。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://github.com/redis/hiredis/security/advisories/GHSA-hfm9-39pp-55p2
参考网址
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2021/10/msg00007.html
来源:CONFIRM
链接:https://github.com/redis/hiredis/security/advisories/GHSA-hfm9-39pp-55p2
来源:MISC
链接:https://wiki.sei.cmu.edu/confluence/display/c/MEM07-C.+Ensure+that+the+arguments+to+calloc%28%29%2C+when+multiplied%2C+do+not+wrap
来源:MISC
链接:https://github.com/redis/hiredis/commit/76a7b10005c70babee357a7d0f2becf28ec7ed1e
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20211104-0003/
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2021-32765
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3377
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Hiredis-integer-overflow-via-RESP-Mult-bulk-Protocol-Data-36633
受影响实体
暂无
补丁
- Hiredis 输入验证错误漏洞的修复措施<!--2021-10-4-->
还没有评论,来说两句吧...