First published: Mon Jul 25 2016(Updated: )
linenoise, as used in Redis before 3.2.3, uses world-readable permissions for .rediscli_history, which allows local users to obtain sensitive information by reading the file.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
Redislabs Redis | <=3.2.2 | |
Debian Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.