7.5
CVSSv3

CVE-2020-7105

Published: 16/01/2020 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

async.c and dict.c in libhiredis.a in hiredis up to and including 0.14.0 allow a NULL pointer dereference because malloc return values are unchecked.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redislabs hiredis

debian debian linux 8.0

fedoraproject fedora 30

fedoraproject fedora 31

Vendor Advisories

Debian Bug report logs - #949995 hiredis: CVE-2020-7105 Package: src:hiredis; Maintainer for src:hiredis is Chris Lamb <lamby@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 28 Jan 2020 07:39:01 UTC Severity: important Tags: security, upstream Found in versions hiredis/0140-4, hiredis ...