Bugzilla – Bug 991250
VUL-0: CVE-2013-7458: redis: World readable .rediscli_history
Last modified: 2020-11-11 14:36:12 UTC
http://seclists.org/oss-sec/2016/q3/189 https://bugs.debian.org/832460 redis-cli stores its history in ~/.rediscli_history, this file is created with permissions 0644. Home folders are world readable as well in debian, so any user can access other users' redis history, including AUTH commands, which include credentials. I've contacted upstream on 2016-05-30 without any reaction at all and discovered this bug was first reported 3 years ago, still unfixed. @RedisLabs keeps referring to their paid support on twitter. Demo: `cat /home/*/.rediscli_history` Upstream report: https://github.com/antirez/redis/issues/3284 https://github.com/antirez/redis/pull/3322 https://github.com/antirez/redis/pull/1418 References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-7458 http://seclists.org/oss-sec/2016/q3/189 http://people.canonical.com/~ubuntu-security/cve/2013/CVE-2013-7458.html https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=832460
https://github.com/antirez/redis/commit/9d524114eda67dedc38a9f97c9d5f3a5c3747829 https://github.com/antirez/redis/commit/71536684a788dc859e42132a2c5a2b7373414375
openSUSE:13.2:Update/redis 2.8.22 openSUSE:Backports:SLE-12/redis 3.0.7 (sbahling) openSUSE:Leap:42.1:Update/redis 3.0.4
https://build.opensuse.org/request/show/416021 https://build.opensuse.org/request/show/416022 pending maintainer reviews
This is an autogenerated message for OBS integration: This bug (991250) was mentioned in https://build.opensuse.org/request/show/416076 13.2+42.1 / redis
This is an autogenerated message for OBS integration: This bug (991250) was mentioned in https://build.opensuse.org/request/show/416077 Backports:SLE-12 / redis
release update
openSUSE-SU-2016:1980-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 991250 CVE References: CVE-2013-7458 Sources used: SUSE Package Hub for SUSE Linux Enterprise 12 (src): redis-3.0.7-6.1
openSUSE-SU-2016:1981-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 991250 CVE References: CVE-2013-7458 Sources used: openSUSE Leap 42.1 (src): redis-3.0.4-6.1 openSUSE 13.2 (src): redis-2.8.22-2.12.1
SUSE-OU-2020:3291-1: An update that solves 7 vulnerabilities, contains four features and has two fixes is now available. Category: optional (moderate) Bug References: 1002351,1047218,1061967,1064980,1097430,1131555,798455,835815,991250 CVE References: CVE-2013-7458,CVE-2015-8080,CVE-2016-10517,CVE-2016-8339,CVE-2017-15047,CVE-2018-11218,CVE-2018-11219 JIRA References: ECO-2417,ECO-2867,SLE-11578,SLE-12821 Sources used: SUSE Linux Enterprise Module for Server Applications 15-SP2 (src): redis-6.0.8-1.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.