Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1000115

Опубликовано: 02 мар. 2018
Источник: redhat
CVSS3: 5.3
EPSS Высокий

Описание

Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic amplification of 1:50,000 has been reported by reliable sources). This attack appear to be exploitable via network connectivity to port 11211 UDP. This vulnerability appears to have been fixed in 1.5.6 due to the disabling of the UDP protocol by default.

It was discovered that the memcached connections using UDP transport protocol can be abused for efficient traffic amplification distributed denial of service (DDoS) attacks. A remote attacker could send a malicious UDP request using a spoofed source IP address of a target system to memcached, causing it to send a significantly larger response to the target.

Отчет

Red Hat is aware of traffic amplification distributed denial of service (DDoS) attacks that take advantage of the insecurely configured memcached servers reachable from the public Internet. The default configuration of memcached as shipped in Red Hat products makes it possible to abuse them for these DDoS attacks if memcached is exposed to connections from the public Internet. Refer to the Red Hat Knowledgebase article 3369081 for instructions on how to properly secure memcached installations to prevent them from being used in the attack. https://access.redhat.com/solutions/3369081

Меры по смягчению последствий

Please refer to the Red Hat Knowledgebase article 3369081 for instructions on how to properly secure memcached installations to prevent them from being used in an attack. https://access.redhat.com/solutions/3369081

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6memcachedWill not fix
Red Hat Enterprise Linux 7memcachedWill not fix
Red Hat Enterprise Linux 8memcachedNot affected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)memcachedWill not fix
Red Hat Mobile Application Platform 4rhmap-memcached-dockerWill not fix
Red Hat OpenStack Platform 13 (Queens)memcachedAffected
Red Hat OpenStack Platform 8 (Liberty)memcachedAffected
Red Hat OpenStack Platform 9 (Mitaka)memcachedAffected
Red Hat OpenStack Platform 10.0 (Newton)openstack-tripleo-heat-templatesFixedRHSA-2018:159317.05.2018
Red Hat OpenStack Platform 10.0 (Newton)puppet-tripleoFixedRHSA-2018:159317.05.2018

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1551182memcached: UDP server support allows spoofed traffic amplification DoS

EPSS

Процентиль: 99%
0.82527
Высокий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 8 лет назад

Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic amplification of 1:50,000 has been reported by reliable sources). This attack appear to be exploitable via network connectivity to port 11211 UDP. This vulnerability appears to have been fixed in 1.5.6 due to the disabling of the UDP protocol by default.

CVSS3: 7.5
nvd
почти 8 лет назад

Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic amplification of 1:50,000 has been reported by reliable sources). This attack appear to be exploitable via network connectivity to port 11211 UDP. This vulnerability appears to have been fixed in 1.5.6 due to the disabling of the UDP protocol by default.

CVSS3: 7.5
debian
почти 8 лет назад

Memcached version 1.5.5 contains an Insufficient Control of Network Me ...

suse-cvrf
почти 8 лет назад

Security update for memcached

suse-cvrf
больше 7 лет назад

Security update for memcached

EPSS

Процентиль: 99%
0.82527
Высокий

5.3 Medium

CVSS3