summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorYasuhiro Kimura <yasu@FreeBSD.org>2024-10-03 08:22:48 +0900
committerYasuhiro Kimura <yasu@FreeBSD.org>2024-10-03 08:56:04 +0900
commite44e4021e418c8df15aa918517a60288af9967e2 (patch)
tree58bb2f8a6583e6d78ec6bee99584252902bcb5b0
parentsecurity/ca_root_nss: Update to 3.104 (diff)
security/vuxml: Document multiple valnerabilities in Redis and Valkey
-rw-r--r--security/vuxml/vuln/2024.xml48
1 files changed, 48 insertions, 0 deletions
diff --git a/security/vuxml/vuln/2024.xml b/security/vuxml/vuln/2024.xml
index 2ae31ecc56e5..8d0ca7bf293d 100644
--- a/security/vuxml/vuln/2024.xml
+++ b/security/vuxml/vuln/2024.xml
@@ -1,3 +1,51 @@
+ <vuln vid="8b20f21a-8113-11ef-b988-08002784c58d">
+ <topic>redis,valkey -- Multiple vulnerabilities</topic>
+ <affects>
+ <package>
+ <name>redis</name>
+ <range><ge>7.4.0</ge><lt>7.4.1</lt></range>
+ </package>
+ <package>
+ <name>redis72</name>
+ <range><ge>7.2.0</ge><lt>7.2.6</lt></range>
+ </package>
+ <package>
+ <name>redis62</name>
+ <range><ge>6.2.0</ge><lt>6.2.16</lt></range>
+ </package>
+ <package>
+ <name>valkey</name>
+ <range><ge>8,0,0</ge><lt>8.0.1</lt></range>
+ <range><ge>7.2.0</ge><lt>7.2.7</lt></range>
+ </package>
+ </affects>
+ <description>
+ <body xmlns="http://www.w3.org/1999/xhtml">
+ <p>Redis core team reports:</p>
+ <blockquote cite="https://github.com/redis/redis/releases/tag/7.4.1">
+ <dl>
+ <dt>CVE-2024-31449</dt>
+ <dd>Lua library commands may lead to stack overflow and potential RCE.</dd>
+ <dt>CVE-2024-31227</dt>
+ <dd>Potential Denial-of-service due to malformed ACL selectors.</dd>
+ <dt>CVE-2024-31228</dt>
+ <dd>Potential Denial-of-service due to unbounded pattern matching.</dd>
+ </dl>
+ </blockquote>
+ </body>
+ </description>
+ <references>
+ <cvename>CVE-2024-31449</cvename>
+ <cvename>CVE-2024-31227</cvename>
+ <cvename>CVE-2024-31228</cvename>
+ <url>https://github.com/redis/redis/releases/tag/7.4.1</url>
+ </references>
+ <dates>
+ <discovery>2024-10-02</discovery>
+ <entry>2024-10-02</entry>
+ </dates>
+ </vuln>
+
<vuln vid="fe5c1e7a-7eed-11ef-9533-f875a43e1796">
<topic>php -- Multiple vulnerabilities</topic>
<affects>