Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Debian: DSA-3634-1 Moderate Security Advisory for Redis Permissions

debian
Calendar Grey July 30, 2016
Debian Logo
Enhance your Debian Redis security by configuring proper permissions for history files. Follow the steps outlined to secure access effectively
It was discovered that redis, a persistent key-value database, did not properly protect redis-cli history files: they were created by default with world-readable permissions

Summary

Users and systems administrators may want to proactively change
permissions on existing ~/rediscli_history files, instead of waiting
for the updated redis-cli to do so the next time it is run.

For the stable distribution (jessie), this problem has been fixed in
version 2:2.8.17-1+deb8u5.

For the testing (stretch) and unstable (sid) distributions, this
problem has been fixed in version 2:3.2.1-4.

We recommend that you upgrade your redis packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
important
Lowest
Low
Medium
High
Critical

Package: redis
CVE ID: CVE-2013-7458

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here