networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port).
[
{
"target": {
"file": "src/server.c"
},
"source": "https://github.com/antirez/redis/commit/874804da0c014a7d704b3d285aa500098a931f50",
"deprecated": false,
"id": "CVE-2016-10517-34fc378b",
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"124880604520077166671741876553448855320",
"17607989238585627192006328325640026296",
"316040378880908604113778517788260677767",
"93458149514543909809984600211885125528"
]
}
},
{
"target": {
"file": "src/server.h"
},
"source": "https://github.com/antirez/redis/commit/874804da0c014a7d704b3d285aa500098a931f50",
"deprecated": false,
"id": "CVE-2016-10517-8b5e18a9",
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"293441393269233123675708999680469895646",
"70362983986487224871491241103974749383",
"205390326808090795749215624981622578027",
"304632248323533289008649620454653853583"
]
}
},
{
"target": {
"file": "src/networking.c"
},
"source": "https://github.com/antirez/redis/commit/874804da0c014a7d704b3d285aa500098a931f50",
"deprecated": false,
"id": "CVE-2016-10517-c30ff40c",
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"163148284592519125185901164272060612753",
"70451653832058093279536878907119473300",
"215185346124952849263144259165636240912",
"100079807825566757584135242790465355990",
"199479240253159866632050854038291740593",
"245006625046125700008417689478308844302",
"96178466864819807631888675772326466251"
]
}
},
{
"target": {
"function": "processInputBuffer",
"file": "src/networking.c"
},
"source": "https://github.com/antirez/redis/commit/874804da0c014a7d704b3d285aa500098a931f50",
"deprecated": false,
"id": "CVE-2016-10517-f00326f7",
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"function_hash": "152124302612145123004825358630729190358",
"length": 876.0
}
}
]