Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2016-8339

buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted…

Technology

Redis

CVSS Score

9.8 / 10.0

Affected Versions

3.2.0; 3.2.1; 3.2.2; 3.2.3

Upstream Fix

See upstream advisory

Published

October 28, 2016

OSSeva Coverage

Fixed upstream

Description

A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent. An out of bounds write vulnerability exists in the handling of the client-output-buffer-limit option during the CONFIG SET command for the Redis data structure store. A crafted CONFIG SET command can lead to an out of bounds write potentially resulting in code execution.

Is your Redis deployment affected?

If you're running 3.2.0; 3.2.1; 3.2.2; 3.2.3, you need this patch. Book a discovery call to get covered.