Debian Security Advisory
DSA-4480-1 redis -- security update
- Date Reported:
- 11 Jul 2019
- Affected Packages:
- redis
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2019-10192, CVE-2019-10193.
- More information:
-
Multiple vulnerabilities were discovered in the HyperLogLog implementation of Redis, a persistent key-value database, which could result in denial of service or potentially the execution of arbitrary code.
For the oldstable distribution (stretch), these problems have been fixed in version 3:3.2.6-3+deb9u3.
For the stable distribution (buster), these problems have been fixed in version 5:5.0.3-4+deb10u1.
We recommend that you upgrade your redis packages.
For the detailed security status of redis please refer to its security tracker page at: https://security-tracker.debian.org/tracker/redis