Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

REDIS ON WINDOWS DBGHELP.DLL UNCONTROLLED SEARCH PATH #272

Open
iav20 opened this issue Nov 15, 2022 · 0 comments
Open

REDIS ON WINDOWS DBGHELP.DLL UNCONTROLLED SEARCH PATH #272

iav20 opened this issue Nov 15, 2022 · 0 comments

Comments

@iav20
Copy link

iav20 commented Nov 15, 2022

A vulnerability was found in Redis on Windows (the affected version is unknown). It has been declared as critical.

This vulnerability affects an unknown functionality in the library C:/Program Files/Redis/dbghelp.dll. The manipulation with an unknown input leads to a privilege escalation vulnerability. The CWE definition for the vulnerability is CWE-427.

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors. As an impact it is known to affect confidentiality, integrity, and availability.

The weakness was released 10/28/2022. The advisory is shared for download at cnblogs.com.

Refer https://vuldb.com/?id.212416 for more details

Please let us know about the impact of the issue and by when and in which version this issue can be expected to get fixed ?

Best Regards,
Apoorv

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant