REDHAT-BUG-2174305: Integer Overflow
(CVE-2023-25155) Specially crafted SRANDMEMBER, ZRANDMEMBER, and HRANDFIELD commands can trigger an integer overflow, resulting in a runtime assertion and termination of the Redis server process. https://github.com/gentoo/gentoo/pull/29860
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2174305?
REDHAT-BUG-2174305 is classified as a critical vulnerability due to the potential for integer overflow leading to server termination.
How do I fix REDHAT-BUG-2174305?
To fix REDHAT-BUG-2174305, it is recommended to apply the latest security patches from the Redis maintainers or upgrade to a fixed version.
What are the affected commands in REDHAT-BUG-2174305?
The affected commands in REDHAT-BUG-2174305 are SRANDMEMBER, ZRANDMEMBER, and HRANDFIELD.
What can happen if REDHAT-BUG-2174305 is exploited?
If REDHAT-BUG-2174305 is exploited, it can lead to an integer overflow, resulting in a runtime assertion failure and termination of the Redis server.
Is REDHAT-BUG-2174305 a remote vulnerability?
Yes, REDHAT-BUG-2174305 can potentially be executed remotely by sending specially crafted commands to the Redis server.