redislabs redis CVE-2021-3470 is a vulnerability in Redis Labs Redis
Published on March 31, 2021

A heap overflow issue was found in Redis in versions before 5.0.10, before 6.0.9 and before 6.2.0 when using a heap allocator other than jemalloc or glibc's malloc, leading to potential out of bound write or process crash. Effectively this flaw does not affect the vast majority of users, who use jemalloc or glibc malloc.

NVD

Weakness Type

What is a Buffer Overflow Vulnerability?

The software performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

CVE-2021-3470 has been classified to as a Buffer Overflow vulnerability or weakness.


Products Associated with CVE-2021-3470

Want to know whenever a new CVE is published for Redis Labs Redis? stack.watch will email you.

 

Exploit Probability

EPSS
0.67%
Percentile
70.93%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.