Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Debian 7 Wheezy Redis DLA-1161-1 Moderate Cross Protocol Attack

debian lts
Calendar Grey November 5, 2017
Dist Debian Esm H88
A recent Redis security patch fixes a critical cross-protocol scripting vulnerability impacting Debian Wheezy, along with suggested upgrade procedures.
It was discovered that there was a "Cross Protocol Scripting" attack in the Redis key-value database

Summary

"POST" and "Host:" command strings (which are not valid in the Redis
protocol) were not immediately rejected when an attacker makes HTTP
request to the Redis TCP port.

For Debian 7 "Wheezy", this issue has been fixed in redis version
2:2.4.14-1+deb7u2.

We recommend that you upgrade your redis packages.


Regards,

- --
,'`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-



Severity
important
Lowest
Low
Medium
High
Critical

Package: redis
Version: 2:2.4.14-1+deb7u2
CVE ID: CVE-2016-1051

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here