CVE-2016-0206
published 2017-02-08CVE-2016-0206: IBM Cloud Orchestrator could allow a local authenticated attacker to cause the server to slow down for a short period of time by using a specially crafted and…
PriorityP410low3.3CVSS 3.0
AVLACLPRLUINSUCNINAL
EPSS
0.30%
22.3th percentile
IBM Cloud Orchestrator could allow a local authenticated attacker to cause the server to slow down for a short period of time by using a specially crafted and malformed URL.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | cloud_orchestrator | — | — |
| ibm | cloud_orchestrator | — | — |
| ibm | cloud_orchestrator | — | — |
| ibm | cloud_orchestrator | — | — |
| ibm | cloud_orchestrator | — | — |
| ibm_corporation | cloud_orchestrator | — | — |
| ibm_corporation | cloud_orchestrator | — | — |
| ibm_corporation | cloud_orchestrator | — | — |
| ibm_corporation | cloud_orchestrator | — | — |
| ibm_corporation | cloud_orchestrator | — | — |
| ibm_corporation | cloud_orchestrator | — | — |
| ibm_corporation | cloud_orchestrator | — | — |
| ibm_corporation | cloud_orchestrator | — | — |
| ibm_corporation | cloud_orchestrator | — | — |
| ibm_corporation | cloud_orchestrator | — | — |
| ibm_corporation | cloud_orchestrator | — | — |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-8339 redis: OOB write vulnerability in handling of client-output-buffer-limit option during the CONFIG SET command
bugzilla·2016-10-03·CVSS 9.8
CVE-2016-8339 [CRITICAL] CVE-2016-8339 redis: OOB write vulnerability in handling of client-output-buffer-limit option during the CONFIG SET command
CVE-2016-8339 redis: OOB write vulnerability in handling of client-output-buffer-limit option during the CONFIG SET command
An out of bounds write vulnerability was found in the handling of the client-output-buffer-limit option during the CONFIG SET command for the Redis data structure store. A crafted CONFIG SET command can lead to an out of bounds write potentially resulting in code execution.
Upstream patch:
https://github.com/antirez/redis/commit/6d9f8e2462fc2c426d48c941edeb78e5df7d2977
External References:
http://www.talosintelligence.com/reports/TALOS-2016-0206/
http://blog.talosintel.com/2016/09/redis-vulnerability.html
Discussion:
Statement:
No currently supported version of Red Hat OpenStack Platform or Red Hat Enterprise Linux OpenStack Platform is affected by this flaw.
Talos
Vulnerability Spotlight: Redis CONFIG SET client-output-buffer-limit Code Execution Vulnerability
blogs_talos·2016-09-30·CVSS 9.8
CVE-2016-8339 [CRITICAL] Vulnerability Spotlight: Redis CONFIG SET client-output-buffer-limit Code Execution Vulnerability
Vulnerability Discovered by Cory Duplantis of Talos
### Overview Talos is disclosingTALOS-2016-0206/CVE-2016-8339, an out-of-bounds write vulnerability inRedis. Redis is a simple in-memory data structure store using a key-value model. Redis has been growing in popularity due to its ability to handle problems that other databases can't solve or are inherently slow at. This particular vulnerability exists in the handling of the client-output-buffer-limit option during the CONFIG SET command for the Redis data structure store. A crafted CONFIG SET command can lead to an out of bounds write, potentially resulting in code execution.
### Details An out of bounds write vulnerability exists during the modification of the `client-output-buffer-limit` option using the `CONFIG SET` command. The req
2017-02-08
Published