Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Arkamar

#35668of 56,326
7.8Total CVSS
Vulnerabilities · 1
PT-2022-5226
7.8
2022-10-21
Redis · Redis · CVE-2022-3647
**Name of the Vulnerable Software and Affected Versions** Redis versions up to 6.2.7/7.0.5 **Description** A vulnerability was found in the function `sigsegvHandler` of the file debug.c of the component Crash Report. The manipulation leads to denial of service. The complexity of an attack is rather high. The exploitability is told to be difficult. The real existence of this vulnerability is still doubted at the moment. The vendor claims that this is not a DoS because it applies to the crash logging mechanism which is triggered after a crash has occurred. **Recommendations** Upgrading to version 6.2.8 and 7.0.6 is able to address this issue. It is recommended to apply a patch to fix this issue, the patch is identified as 0bf90d944313919eb8e63d3588bf63a367f020a3. As a temporary workaround, consider disabling the `sigsegvHandler` function until a patch is available.