USN-5221-1
Dashboard / Vulnerabilities / USN-5221-1
USN-5221-1
Summary: redis vulnerabilities
Details: It was discovered that Redis incorrectly handled certain specially crafted Lua scripts. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2021-32626) It was discovered that Redis incorrectly handled some malformed requests when using Redis Lua Debugger. A remote attacker could possibly use this issue to cause a denial of service or other unspecified impact. This issue only affected Ubuntu 18.04 ESM and Ubuntu 20.04 ESM. (CVE-2021-32672) It was discovered that Redis incorrectly handled certain Redis Standard Protocol (RESP) requests. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2021-32675) It was discovered that Redis incorrectly handled some configuration parameters with specially crafted network payloads. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. Vulnerabilities CVE-2021-32627 and CVE-2021-41099 only affected Ubuntu 18.04 ESM and Ubuntu 20.04 ESM. (CVE-2021-32627, CVE-2021-32628, CVE-2021-32687, CVE-2021-41099). It was discovered that Redis incorrectly handled memory when processing certain input in 32-bit systems. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. One vulnerability (CVE-2021-32761) only affected Ubuntu 14.04 ESM, Ubuntu 16.04 ESM and Ubuntu 18.04 ESM and another vulnerability (CVE-2021-21309) only affected Ubuntu 18.04 ESM. (CVE-2021-32761, CVE-2021-21309).
References: https://ubuntu.com/security/notices/USN-5221-1, https://ubuntu.com/security/CVE-2021-21309, https://ubuntu.com/security/CVE-2021-32626, https://ubuntu.com/security/CVE-2021-32627, https://ubuntu.com/security/CVE-2021-32628, https://ubuntu.com/security/CVE-2021-32672, https://ubuntu.com/security/CVE-2021-32675, https://ubuntu.com/security/CVE-2021-32687, https://ubuntu.com/security/CVE-2021-32761, https://ubuntu.com/security/CVE-2021-41099
Affected packages
Package
Name: redis
Purl: pkg:deb/ubuntu/redis?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
