CVE-2020-35668: Null Pointer Dereference
Published Dec 23, 2020
·Updated
RedisGraph 2.x through 2.2.11 has a NULL Pointer Dereference that leads to a server crash because it mishandles an unquoted string, such as an alias that has not yet been introduced.
Affected Software
1 affected component
Redislabs Redisgraph>=2.0.0<2.2.11
Remediation
Patch Available
Event History
Dec 23, 2020
CVE Published
via MITRE·10:32 PM
Data Sourced
via MITRE·10:32 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for RedisGraph?
The vulnerability ID for RedisGraph is CVE-2020-35668.
2
What is the severity rating of CVE-2020-35668?
CVE-2020-35668 has a severity rating of 7.5 (high).
3
How does CVE-2020-35668 affect RedisGraph?
CVE-2020-35668 affects RedisGraph versions 2.x through 2.2.11.
4
What is the impact of CVE-2020-35668?
The impact of CVE-2020-35668 is a NULL pointer dereference that leads to a server crash.
5
Is there a fix available for CVE-2020-35668?
Yes, a fix for CVE-2020-35668 is available. Please refer to the official GitHub issue and pull request for more information.