Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2016-8339
buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted…
Technology
Redis
CVSS Score
9.8 / 10.0
Affected Versions
3.2.0; 3.2.1; 3.2.2; 3.2.3
Upstream Fix
See upstream advisory
Published
October 28, 2016
OSSeva Coverage
Fixed upstream
Description
A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent. An out of bounds write vulnerability exists in the handling of the client-output-buffer-limit option during the CONFIG SET command for the Redis data structure store. A crafted CONFIG SET command can lead to an out of bounds write potentially resulting in code execution.
Is your Redis deployment affected?
If you're running 3.2.0; 3.2.1; 3.2.2; 3.2.3, you need this patch. Book a discovery call to get covered.