[Bug 1191305] VUL-0: CVE-2021-32627,CVE-2021-32628: redis: Integer to heap buffer overflows
6 Oct
2021
6 Oct
'21
13:22
https://bugzilla.suse.com/show_bug.cgi?id=1191305 https://bugzilla.suse.com/show_bug.cgi?id=1191305#c3 --- Comment #3 from Danilo Spinella <danilo.spinella@suse.com> --- While updating to 6.0.16 would have been ideal to fix all the CVEs for redis (bsc#1191299, bsc#1191300, bsc#1191302, bsc#1191303, bsc#1191304, bsc#1191305, bsc#1191306), 6.0.15 introduces a small breaking change: Change reply type for ZPOPMAX/MIN with count in RESP3 to nested array. Was using a flat array like in RESP2 instead of a nested array like ZRANGE does. https://github.com/redis/redis/releases/tag/6.0.15 Therefore I'd prefer to backport the changes manually. -- You are receiving this mail because: You are on the CC list for the bug.
1184
Age (days ago)
1184
Last active (days ago)
0 comments
1 participants
participants (1)
-
bugzilla_noreply@suse.com