QID 355808
Date Published: 2023-08-14
QID 355808: Amazon Linux Security Advisory for redis6 : ALAS2023-2023-291
A heap-based buffer overflow flaw was found in redis.
This flaw allows an attacker to trick an authenticated user into executing a specially crafted lua script in redis.
This attack triggers a heap overflow in the cjson and cmsgpack libraries, resulting in heap corruption and potential remote code execution. (
( CVE-2022-24834)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.
Solution
Please refer to Amazon advisory: ALAS2023-2023-291 for affected packages and patching details, or update with your package manager.
Vendor References
- ALAS2023-2023-291 -
alas.aws.amazon.com/AL2023/ALAS-2023-291.html
CVEs related to QID 355808
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS2023-2023-291 | amazon linux 2023 |
|