Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-9951

Опубликовано: 17 июл. 2017
Источник: debian
EPSS Низкий

Описание

The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation fault) via a request to add/set a key, which makes a comparison between signed and unsigned int and triggers a heap-based buffer over-read. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8705.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
memcachedfixed1.5.0-1package

Примечания

  • https://www.twistlock.com/2017/07/13/cve-2017-9951-heap-overflow-memcached-server-1-4-38-twistlock-vulnerability-report/

  • https://github.com/memcached/memcached/commit/328629445c71e6c17074f6e9e0e3ef585b58f167

EPSS

Процентиль: 82%
0.01674
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation fault) via a request to add/set a key, which makes a comparison between signed and unsigned int and triggers a heap-based buffer over-read. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8705.

CVSS3: 5.3
redhat
больше 8 лет назад

The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation fault) via a request to add/set a key, which makes a comparison between signed and unsigned int and triggers a heap-based buffer over-read. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8705.

CVSS3: 7.5
nvd
больше 8 лет назад

The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation fault) via a request to add/set a key, which makes a comparison between signed and unsigned int and triggers a heap-based buffer over-read. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8705.

suse-cvrf
почти 8 лет назад

Security update for memcached

suse-cvrf
почти 8 лет назад

Security update for memcached

EPSS

Процентиль: 82%
0.01674
Низкий