gpp_maybe
Security update for redis7
SUSE-SLE-Module-Server-Applications-15-SP5-2023-2925
This update for redis7 fixes the following issues: - CVE-2022-24834: Fixed heap overflow in the cjson and cmsgpack libraries (bsc#1213193). - CVE-2023-28856: Fixed HINCRBYFLOAT invalid key crash (bsc#1210548). - CVE-2022-36021: Fixed integer overflow via Specially crafted SRANDMEMBER, ZRANDMEMBER, and HRANDFIELD (bsc#1208790). - CVE-2023-25155: Fixed Integer Overflow in RAND commands (bsc#1208793). - CVE-2023-28425: Fixed denial-of-service via Specially crafted MSETNX command (bsc#1209528). - CVE-2023-36824: Fixed heap overflow in COMMAND GETKEYS and ACL evaluation (bsc#1213249).
-
Release DateJul 20 2023
-
ReferencesBugzilla: 1213193, 1213249, 1208790, 1210548, 1208793, 1209528
CVEs: CVE-2022-36021, CVE-2022-24834, CVE-2023-36824, CVE-2023-28856, CVE-2023-25155, CVE-2023-28425 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Server Applications Module 15.5 s390x
-
Packages
Server Applications Module 15.5 aarch64
-
Packages
Server Applications Module 15.5 ppc64le
-
Packages
Server Applications Module 15.5 x86_64
-
Packages