Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-9951

Опубликовано: 17 июл. 2017
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation fault) via a request to add/set a key, which makes a comparison between signed and unsigned int and triggers a heap-based buffer over-read. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8705.

Отчет

Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Меры по смягчению последствий

This flaw is in the memcached binary protocol. If your client programs only use the ASCII protocol when communicating with memcached, you can disable the binary protocol and protect against this flaw by adding "-B ascii" to OPTIONS in /etc/sysconfig/memcached.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6memcachedWill not fix
Red Hat Enterprise Linux 7memcachedWill not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)memcachedWill not fix
Red Hat Mobile Application Platform 4memcachedWill not fix
Red Hat OpenStack Platform 10 (Newton)memcachedWill not fix
Red Hat OpenStack Platform 11 (Ocata)memcachedWill not fix
Red Hat OpenStack Platform 12 (Pike)memcachedNot affected
Red Hat OpenStack Platform 8 (Liberty)memcachedWill not fix
Red Hat OpenStack Platform 9 (Mitaka)memcachedWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1471970memcached: Heap-based buffer over-read in try_read_command function (incomplete fix for CVE-2016-8705)

EPSS

Процентиль: 90%
0.04166
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 9 лет назад

The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation fault) via a request to add/set a key, which makes a comparison between signed and unsigned int and triggers a heap-based buffer over-read. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8705.

CVSS3: 7.5
nvd
около 9 лет назад

The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation fault) via a request to add/set a key, which makes a comparison between signed and unsigned int and triggers a heap-based buffer over-read. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8705.

CVSS3: 7.5
debian
около 9 лет назад

The try_read_command function in memcached.c in memcached before 1.4.3 ...

suse-cvrf
больше 8 лет назад

Security update for memcached

suse-cvrf
больше 8 лет назад

Security update for memcached

EPSS

Процентиль: 90%
0.04166
Низкий

5.3 Medium

CVSS3