CVE-2017-15047

EUVD-2017-6522
The clusterLoadConfig function in cluster.c in Redis 4.0.2 allows attackers to cause a denial of service (out-of-bounds array index and application crash) or possibly have unspecified other impact by leveraging "limited access to the machine."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
Affected Products (NVD)
VendorProductVersion
redislabsredis
4.0.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
redis
bookworm
5:7.0.15-1~deb12u1
fixed
bookworm (security)
5:7.0.15-1~deb12u1
fixed
bullseye
5:6.0.16-1+deb11u2
fixed
bullseye (security)
5:6.0.16-1+deb11u3
fixed
jessie
not-affected
sid
5:7.0.15-2
fixed
trixie
5:7.0.15-2
fixed
wheezy
not-affected
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
redis
artful
ignored
bionic
not-affected
trusty
not-affected
xenial
Fixed 2:3.0.6-1ubuntu0.2
released
zesty
ignored