Advisory Published
Updated

REDHAT-BUG-894659

First published: Sat Jan 12 2013(Updated: )

It seems that redis 2.4 use a predictible file name in /tmp/ as some kind of swap file : server.vm_swap_file = zstrdup("/tmp/redis-%p.vm"); this was removed in 2.6 ( deprecated code ), but 2.4 is in fedora 18 and epel 6 AFAIK. Since redis do not care if the file exist or not before opening it ( and in fact, I think it try to reuse if it already exist ), this could be used by a attacker to erase a arbitrary file with a symlink to the file. Depending if redis is running as root or not, this could be dangerous, or just a minor nuisance.

Affected SoftwareAffected VersionHow to fix
ioredis

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of REDHAT-BUG-894659?

    The severity of REDHAT-BUG-894659 is moderate, as the predictable file name in /tmp/ can lead to potential security risks.

  • How do I fix REDHAT-BUG-894659?

    To fix REDHAT-BUG-894659, it is recommended to upgrade Redis to version 2.6 or later, where this issue has been resolved.

  • Which versions of Redis are affected by REDHAT-BUG-894659?

    REDHAT-BUG-894659 affects Redis version 2.4 and earlier, as the predictable swap file issue was addressed in version 2.6.

  • Can the predictable swap file issue in REDHAT-BUG-894659 lead to data loss?

    Yes, the predictable swap file issue in REDHAT-BUG-894659 can potentially lead to data loss or corruption if multiple instances of Redis are running on the same server.

  • Is REDHAT-BUG-894659 a common vulnerability?

    Yes, REDHAT-BUG-894659 is a recognized vulnerability in older versions of Redis and is particularly noted in Fedora 18 and EPEL 6.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203