Redis Raft ODR Violation
2024-1-18 23:29:31 Author: packetstormsecurity.com(查看原文) 阅读量:11 收藏

[Suggested description]
Redis raft master-1b8bd86 to master-7b46079 was discovered to contain an ODR violation via the component hiredisAllocFns at /opt/fs/redisraft/deps/hiredis/alloc.c.

[VulnerabilityType Other]
AddressSanitizer: odr-violation

[Vendor of Product]
Redis

[Affected Product Code Base]
raft - master-1b8bd86 to master-7b46079

[Affected Component]
affected executable

[Attack Type]
Remote

[Impact Code execution]
true

[Impact Denial of Service]
true

[Attack Vectors]
run redis with redisraft

[Reference]
https://github.com/RedisLabs/redisraft/issues/600

[Has vendor confirmed or acknowledged the vulnerability?]
true

[Discoverer]
jerrytesting


文章来源: https://packetstormsecurity.com/files/176624/redisraft-odr.txt
如有侵权请联系:admin#unsafe.sh