Bug 1204633 (CVE-2022-3647)

Summary: VUL-1: CVE-2022-3647: redis: crash in sigsegvHandler debug function
Product: [Novell Products] SUSE Security Incidents Reporter: Carlos López <carlos.lopez>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: NEW --- QA Contact: Security Team bot <security-team>
Severity: Minor    
Priority: P4 - Low CC: danilo.spinella, security-team
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/346041/
Whiteboard: CVSSv3.1:SUSE:CVE-2022-3647:0.0:(AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:N)
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Carlos López 2022-10-24 08:53:00 UTC
rh#2137209

A vulnerability, which was classified as problematic, was found in Redis. Affected is the function sigsegvHandler of the file debug.c of the component Crash Report. The manipulation leads to denial of service. The name of the patch is 0bf90d944313919eb8e63d3588bf63a367f020a3. It is recommended to apply a patch to fix this issue. VDB-211962 is the identifier assigned to this vulnerability.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=2137209
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-3647
https://www.cve.org/CVERecord?id=CVE-2022-3647
https://github.com/redis/redis/commit/0bf90d944313919eb8e63d3588bf63a367f020a3
https://vuldb.com/?id.211962
Comment 4 Swamp Workflow Management 2022-11-22 17:20:52 UTC
SUSE-SU-2022:4168-1: An update that fixes one vulnerability is now available.

Category: security (low)
Bug References: 1204633
CVE References: CVE-2022-3647
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    redis-6.2.6-150400.3.6.1
SUSE Linux Enterprise Module for Server Applications 15-SP4 (src):    redis-6.2.6-150400.3.6.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 5 Swamp Workflow Management 2022-11-22 17:21:29 UTC
SUSE-SU-2022:4169-1: An update that fixes one vulnerability is now available.

Category: security (low)
Bug References: 1204633
CVE References: CVE-2022-3647
JIRA References: 
Sources used:
openSUSE Leap 15.3 (src):    redis-6.0.14-150200.6.14.1
SUSE Linux Enterprise Module for Server Applications 15-SP3 (src):    redis-6.0.14-150200.6.14.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.