"value":"RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 and 2.6.10, specially crafted `CF.LOADCHUNK` commands may be used by authenticated users to perform heap overflow, which may lead to remote code execution. The problem is fixed in RedisBloom 2.4.7 and 2.6.10.\n"
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-122: Heap-based Buffer Overflow",
"cweId":"CWE-122"
}
]
},
{
"description":[
{
"lang":"eng",
"value":"CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')",