APP: Redis XAUTOCLAIM command COUNT Integer Overflow

This signature detects attempts to exploit a known vulnerability against Redis. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the server.

Extended Description

Redis is an in-memory database that persists on disk. Versions 7.0.0 and above, prior to 7.0.5 are vulnerable to an Integer Overflow. Executing an `XAUTOCLAIM` command on a stream key in a specific state, with a specially crafted `COUNT` argument may cause an integer overflow, a subsequent heap overflow, and potentially lead to remote code execution. This has been patched in Redis version 7.0.5. No known workarounds exist.

Affected Products

Redis redis

Short Name
APP:REDIS-XAUTOCLAIM-CMD
Severity
Major
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
COUNT CVE-2022-35951 CVE-2022-35977 CVE-2023-22458 Integer Overflow Redis XAUTOCLAIM command
Release Date
11/07/2022
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

Sigpack Version
3590
False Positive
Unknown
Vendors

Fedoraproject

Redis

Found a potential security threat?