It was discovered that there was a "Cross Protocol Scripting" attack in the Redis key-value database. "POST" and "Host:" command strings (which are not valid in the Redis . Hash: SHA256 Package : redis Version : 2:2.4.14-1+deb7u2 CVE ID : CVE-2016-1051 It was discovered that there was a "Cross Protocol Scripting" attack in the Redis key-value database. "POST" and "Host:" command strings (which are not valid in the Redis protocol) were not immediately rejected when an attacker makes HTTP request to the Redis TCP port. For Debian 7 "Wheezy", this issue has been fixed in redis version 2:2.4.14-1+deb7u2. We recommend that you upgrade your redis packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'`
Get the latest Linux and open source security news straight to your inbox.