Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-9951

Опубликовано: 17 июл. 2017
Источник: redhat
CVSS3: 5.3

Описание

The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation fault) via a request to add/set a key, which makes a comparison between signed and unsigned int and triggers a heap-based buffer over-read. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8705.

Отчет

Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Меры по смягчению последствий

This flaw is in the memcached binary protocol. If your client programs only use the ASCII protocol when communicating with memcached, you can disable the binary protocol and protect against this flaw by adding "-B ascii" to OPTIONS in /etc/sysconfig/memcached.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6memcachedWill not fix
Red Hat Enterprise Linux 7memcachedWill not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)memcachedWill not fix
Red Hat Mobile Application Platform 4memcachedWill not fix
Red Hat OpenStack Platform 10 (Newton)memcachedWill not fix
Red Hat OpenStack Platform 11 (Ocata)memcachedWill not fix
Red Hat OpenStack Platform 12 (Pike)memcachedNot affected
Red Hat OpenStack Platform 8 (Liberty)memcachedWill not fix
Red Hat OpenStack Platform 9 (Mitaka)memcachedWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1471970memcached: Heap-based buffer over-read in try_read_command function (incomplete fix for CVE-2016-8705)

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation fault) via a request to add/set a key, which makes a comparison between signed and unsigned int and triggers a heap-based buffer over-read. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8705.

CVSS3: 7.5
nvd
больше 8 лет назад

The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation fault) via a request to add/set a key, which makes a comparison between signed and unsigned int and triggers a heap-based buffer over-read. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8705.

CVSS3: 7.5
debian
больше 8 лет назад

The try_read_command function in memcached.c in memcached before 1.4.3 ...

suse-cvrf
почти 8 лет назад

Security update for memcached

suse-cvrf
почти 8 лет назад

Security update for memcached

5.3 Medium

CVSS3