Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.announce.security > #3619

[SECURITY] [DSA 5081-1] redis security update

Path csiph.com!newsfeed.xs4all.nl!newsfeed9.news.xs4all.nl!bofh.it!news.nic.it!robomod
From Moritz Muehlenhoff <jmm@debian.org>
Newsgroups linux.debian.announce.security
Subject [SECURITY] [DSA 5081-1] redis security update
Date Fri, 18 Feb 2022 20:10:01 +0100
Message-ID <DSgNH-2IsT-5@gated-at.bofh.it> (permalink)
X-Original-To debian-security-announce@lists.debian.org
X-Mailbox-Line From debian-security-announce-request@lists.debian.org Fri Feb 18 19:05:36 2022
Old-Return-Path <jmm@seger.debian.org>
X-Amavis-Spam-Status No, score=-16.191 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, DIGITS_LETTERS=1, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FVGT_m_MULTI_ODD=0.02, LDO_WHITELIST=-5, PGPSIGNATURE=-5, RCVD_IN_DNSWL_HI=-5, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no
Old-Dkim-Signature v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From: Date:Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=FjLIyF9Pu5vhcalIWeKhtXXNULFAaSjwxh4RdkejJc0=; b=oh 7PkociISjMEBFmXkgx/dyZ+LGO0etZLiZaPMT0NMXhVeFPZ/zTTC1+zo5Vdt+2FpMctjDt/CokGqB 6bIArhiwN/bRkbR8Mwg/aGXi1gtMKNrmReBfDvJ1Zez4PQw25fSpou5TP8GHsib8YecJ7zJ4WKaN2 pYAo3Zn/r4VFa+pte6MlL3VS/sCa0vJvYuQbLcLlORzPW98jdyPbxDWO1LoBUWE86JtTVNgu0JyJa Jpw3+4RN64yZN3I23pHgMWiXGyveGgM7tGMIMk7yNAHtMx5+i96xLJ7lGTpLJl65jGyJr17oov0Rn jSki5usWn2LlfqbYgFB9PWUyzbW9FN7Q==;
MIME-Version 1.0
Content-Type text/plain; charset=us-ascii
Content-Disposition inline
User-Agent Mutt/1.10.1 (2018-07-13)
X-Debian PGP check passed for security officers
Priority urgent
Reply-To debian-security-announce-request@lists.debian.org
X-Mailing-List <debian-security-announce@lists.debian.org> archive/latest/3977
List-ID <debian-security-announce.lists.debian.org>
List-URL <http://lists.debian.org/debian-security-announce/>
List-Archive https://lists.debian.org/msgid-search/20220218190516.GB19601@seger.debian.org
Approved robomod@news.nic.it
Lines 49
Organization linux.* mail to news gateway
Sender robomod@news.nic.it
X-Original-Date Fri, 18 Feb 2022 19:05:16 +0000
X-Original-Message-ID <20220218190516.GB19601@seger.debian.org>
Xref csiph.com linux.debian.announce.security:3619

Show key headers only | View raw


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5081-1                   security@debian.org
https://www.debian.org/security/                       Moritz Muehlenhoff
February 18, 2022                     https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : redis
CVE ID         : CVE-2022-0543
Debian Bug     : 1005787

Reginaldo Silva discovered a (Debian-specific) Lua sandbox escape in
Redis, a persistent key-value database.

For the oldstable distribution (buster), this problem has been fixed
in version 5:5.0.14-1+deb10u2.

For the stable distribution (bullseye), this problem has been fixed in
version 5:6.0.16-1+deb11u2.

We recommend that you upgrade your redis packages.

For the detailed security status of redis please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/redis

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmIP7GsACgkQEMKTtsN8
TjZKCQ/8DREEhcmRf7ZbW3VSDHNsACeCK8QD+ZqRojpKJ9yJZZRiCItcoHiR34+P
WkQbVphIImYD/W/tGPNPIyaxfVKo+T+DcwoCu1MNIGu25vot52cvMi65MqtRKeks
3btiDGueHWhaCv/9shLqghOqL0/qsjh1wH4C4MMKNjQSjBNlrbrrkyrYYF9jUi2s
JQrLnV6o2SU8b5kUtn11FrZmYLz5tlLMKa+ZmyOABQ8UGoDZwYnPXViHCOA5E9i1
BZDXM39HGZ0WllzZXgLzPwWNVGHbiySHRXq4pZAjwQSB92kmi6s2qSAlUnpTYaOa
jWIVFAj6TlHtoLdP8AkCCbDLXGttPwOU3CkwVZ7HBuvVcyQKsD749Letk7jcvpX8
zqwiZbitZ2vf+4y/kd2cpVAHgYN9ET6FZC7GDbbnAV01LHboKVFRUu+GuelIjmO+
7snvlB4CBR1meVruDBdGAPG/NtPPE/Bdaxx4xxNjlufSxu/AE6kRkdW8tLRNKolF
+DTINQbXM1nIx/Xm9dJXnU7ZzF1vZUMZM8ZAl4rIxSA6BetaUxKB7dBhXACidDxR
Qbf+xqFUCXFBUPpfL5TJ1TJMvVmyqVEf80hRr+cna5uuGpJpI0cugHeuh6aJcDIe
htXpsGFf/xRDDEa5VXsE4B9LnCsFegM/Y97XlN4ojDRbURzyYcM=
=E8bU
-----END PGP SIGNATURE-----

Back to linux.debian.announce.security | Previous | Next | Find similar | Unroll thread


Thread

[SECURITY] [DSA 5081-1] redis security update Moritz Muehlenhoff <jmm@debian.org> - 2022-02-18 20:10 +0100

csiph-web