CVE-2020-14147
Summary
| CVE | CVE-2020-14147 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-15 18:15:00 UTC |
| Updated | 2021-07-30 13:59:00 UTC |
| Description | An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly bypass intended sandbox restrictions via a large number, which triggers a stack-based buffer overflow. NOTE: this issue exists because of a CVE-2015-8080 regression. |
Risk And Classification
Problem Types: CWE-787 | CWE-190
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Application | Oracle | Communications Operations Monitor | 3.4 | All | All | All |
| Application | Oracle | Communications Operations Monitor | 4.1 | All | All | All |
| Application | Oracle | Communications Operations Monitor | 4.2 | All | All | All |
| Application | Oracle | Communications Operations Monitor | 4.3 | All | All | All |
| Application | Redislabs | Redis | All | All | All | All |
| Application | Redislabs | Redis | All | All | All | All |
| Operating System | Suse | Linux Enterprise | 12.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-4731-1 redis | DEBIAN | www.debian.org | |
| Redis: Multiple vulnerabilities (GLSA 202008-17) — Gentoo security | GENTOO | security.gentoo.org | |
| [security-announce] openSUSE-SU-2020:1035-1: moderate: Security update f | SUSE | lists.opensuse.org | |
| [FIX] revisit CVE-2015-8080 vulnerability by WOOSEUNGHOON · Pull Request #6875 · redis/redis · GitHub | MISC | github.com | Third Party Advisory |
| Oracle Critical Patch Update Advisory - January 2021 | MISC | www.oracle.com | |
| [FIX] revisit CVE-2015-8080 vulnerability · redis/redis@ef764dd · GitHub | MISC | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 501485 Alpine Linux Security Update for redis
- 504352 Alpine Linux Security Update for redis
- 900107 CBL-Mariner Linux Security Update for redis 5.0.5
- 901623 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (6842-1)
- 903148 Common Base Linux Mariner (CBL-Mariner) Security Update for redis (1878)