Bug 1204633 - (CVE-2022-3647) VUL-1: CVE-2022-3647: redis: crash in sigsegvHandler debug function
(CVE-2022-3647)
VUL-1: CVE-2022-3647: redis: crash in sigsegvHandler debug function
Status: NEW
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P4 - Low : Minor
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/346041/
CVSSv3.1:SUSE:CVE-2022-3647:0.0:(AV:L...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-10-24 08:53 UTC by Carlos López
Modified: 2023-01-25 19:17 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Carlos López 2022-10-24 08:53:00 UTC
rh#2137209

A vulnerability, which was classified as problematic, was found in Redis. Affected is the function sigsegvHandler of the file debug.c of the component Crash Report. The manipulation leads to denial of service. The name of the patch is 0bf90d944313919eb8e63d3588bf63a367f020a3. It is recommended to apply a patch to fix this issue. VDB-211962 is the identifier assigned to this vulnerability.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=2137209
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-3647
https://www.cve.org/CVERecord?id=CVE-2022-3647
https://github.com/redis/redis/commit/0bf90d944313919eb8e63d3588bf63a367f020a3
https://vuldb.com/?id.211962
Comment 4 Swamp Workflow Management 2022-11-22 17:20:52 UTC
SUSE-SU-2022:4168-1: An update that fixes one vulnerability is now available.

Category: security (low)
Bug References: 1204633
CVE References: CVE-2022-3647
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    redis-6.2.6-150400.3.6.1
SUSE Linux Enterprise Module for Server Applications 15-SP4 (src):    redis-6.2.6-150400.3.6.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 5 Swamp Workflow Management 2022-11-22 17:21:29 UTC
SUSE-SU-2022:4169-1: An update that fixes one vulnerability is now available.

Category: security (low)
Bug References: 1204633
CVE References: CVE-2022-3647
JIRA References: 
Sources used:
openSUSE Leap 15.3 (src):    redis-6.0.14-150200.6.14.1
SUSE Linux Enterprise Module for Server Applications 15-SP3 (src):    redis-6.0.14-150200.6.14.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.