Vulnerabilities > CVE-2020-7105 - NULL Pointer Dereference vulnerability in multiple products

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
redislabs
debian
fedoraproject
CWE-476
nessus

Summary

async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference because malloc return values are unchecked.

Vulnerable Configurations

Part Description Count
Application
Redislabs
1
OS
Debian
1
OS
Fedoraproject
2

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2020-53A54EF986.NASL
    descriptionFix for CVE-2020-7105 hiredis: NULL pointer dereference in async.c and dict.c Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-03-18
    modified2020-02-24
    plugin id133886
    published2020-02-24
    reporterThis script is Copyright (C) 2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/133886
    titleFedora 31 : hiredis (2020-53a54ef986)
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DLA-2083.NASL
    descriptionIt was discovered that there were a large number of NULL pointer dereferences due to unchecked return values from malloc and friends in hiredis, a minimalistic C client library. For Debian 8
    last seen2020-06-01
    modified2020-06-02
    plugin id133321
    published2020-01-30
    reporterThis script is Copyright (C) 2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/133321
    titleDebian DLA-2083-1 : hiredis security update
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2020-F6CC7883B8.NASL
    descriptionFix for CVE-2020-7105 hiredis: NULL pointer dereference in async.c and dict.c Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-03-18
    modified2020-02-24
    plugin id133892
    published2020-02-24
    reporterThis script is Copyright (C) 2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/133892
    titleFedora 30 : hiredis (2020-f6cc7883b8)