MGASA-2019-0226 - Updated redis packages fix security vulnerabilities

Publication date: 18 Aug 2019
URL: https://advisories.mageia.org/MGASA-2019-0226.html
Type: security
Affected Mageia releases: 6
CVE: CVE-2019-10192,
     CVE-2019-10193

This update fixes 2 security issues.

A heap-buffer overflow vulnerability was found in the Redis hyperloglog
data structure (CVE-2019-10192).

A stack-buffer overflow vulnerability was found in the Redis hyperloglog
data structure (CVE-2019-10193).

References:
- https://bugs.mageia.org/show_bug.cgi?id=25278
- https://www.debian.org/security/2019/dsa-4480
- https://ubuntu.com/security/notices/USN-4061-1
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10192
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10193

SRPMS:
- 6/core/redis-4.0.14-1.mga6

Mageia 2019-0226: redis security update

This update fixes 2 security issues

Summary

This update fixes 2 security issues.
A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure (CVE-2019-10192).
A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure (CVE-2019-10193).

References

- https://bugs.mageia.org/show_bug.cgi?id=25278

- https://www.debian.org/security/2019/dsa-4480

- https://ubuntu.com/security/notices/USN-4061-1

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10192

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10193

Resolution

MGASA-2019-0226 - Updated redis packages fix security vulnerabilities

SRPMS

- 6/core/redis-4.0.14-1.mga6

Severity
Publication date: 18 Aug 2019
URL: https://advisories.mageia.org/MGASA-2019-0226.html
Type: security
CVE: CVE-2019-10192, CVE-2019-10193

Related News