VDB
BDU%3A2025-04141
BDU%3A2025-04141
PUBLISHED
CVSS 6.5 MEDIUM
Уязвимость функции calloc компонента RESP Handler клиента для взаимодействия с базами данных HIREDIS, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
6.5
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Сообщество свободного программного обеспечения, ООО «РусБИТех-Астра», Redis Labs | Debian GNU/Linux, Astra Linux Special Edition (запись в едином реестре российских программ №369), HIREDIS |
Timeline
- Apr 10, 2025 CVE Published
- May 5, 2025 CVE Updated
References
- https://github.com/redis/hiredis/commit/76a7b10005c70babee357a7d0f2becf28ec7ed1e url
- https://github.com/redis/hiredis/commit/76a7b10005c70babee357a7d0f2becf28ec7ed1e#commitcomment-57544143 url
- https://github.com/redis/hiredis/security/advisories/GHSA-hfm9-39pp-55p2 url
- https://lists.debian.org/debian-lts-announce/2021/10/msg00007.html url
- https://nvd.nist.gov/vuln/detail/CVE-2021-32765 url
- https://security.gentoo.org/glsa/202210-32 url
- https://security.netapp.com/advisory/ntap-20211104-0003/ url
- https://security-tracker.debian.org/tracker/CVE-2021-32765 url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2025-0319SE17 url
- https://wiki.sei.cmu.edu/confluence/display/c/MEM07-C.+Ensure+that+the+arguments+to+calloc%28%29%2C+when+multiplied%2C+do+not+wrap url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2025-0422SE79 url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2025-0422SE47 advisory