Re: Redis for debian and Ubuntu is vulnerable to CVE-2022-24834

2023-07-18 Thread Chris Lamb
Hi Reginaldo, > I'm sending this as a heads up for you folks to pick up last-week's > Redis bugfix if you haven't already, especially > https://github.com/redis/redis/commit/936cfa464f371666c46bff59f7c4247d48973ec6 Thanks for the heads-up. As I understand it, this is CVE-2022-24834 which has been

Redis for debian and Ubuntu is vulnerable to CVE-2022-24834

2023-07-18 Thread Reginaldo Silva
Hi Chris, as well as Debian and Ubuntu security teams I'm sending this as a heads up for you folks to pick up last-week's Redis bugfix if you haven't already, especially https://github.com/redis/redis/commit/936cfa464f371666c46bff59f7c4247d48973ec6 eval 'return cjson.encode(string.rep("a", 357913

Re: Redis for debian and Ubuntu is vulnerable to CVE-2022-24834

2023-07-18 Thread Reginaldo Silva
Cool. TIL that I should really be testing these against sid. Cheers, Reginaldo On Mon, Jul 17, 2023 at 1:40 PM Chris Lamb wrote: > > Hi Reginaldo, > > > I'm sending this as a heads up for you folks to pick up last-week's > > Redis bugfix if you haven't already, especially > > https://github.co