Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1000127

Опубликовано: 27 апр. 2017
Источник: redhat
CVSS3: 6.5

Описание

memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused from free list. This attack appear to be exploitable via network connectivity to the memcached service. This vulnerability appears to have been fixed in 1.4.37 and later.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6memcachedWill not fix
Red Hat Enterprise Linux 7memcachedWill not fix
Red Hat Enterprise Linux 8memcachedNot affected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)memcachedWill not fix
Red Hat Mobile Application Platform 4rhmap-memcached-dockerWill not fix
Red Hat OpenStack Platform 11 (Ocata)memcachedWill not fix
Red Hat OpenStack Platform 12 (Pike)memcachedNot affected
Red Hat OpenStack Platform 13 (Queens)memcachedNot affected
Red Hat OpenStack Platform 8 (Liberty)memcachedWill not fix
Red Hat OpenStack Platform 9 (Mitaka)memcachedWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1555064memcached: Integer Overflow in items.c:item_free()

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 8 лет назад

memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused from free list. This attack appear to be exploitable via network connectivity to the memcached service. This vulnerability appears to have been fixed in 1.4.37 and later.

CVSS3: 7.5
nvd
почти 8 лет назад

memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused from free list. This attack appear to be exploitable via network connectivity to the memcached service. This vulnerability appears to have been fixed in 1.4.37 and later.

CVSS3: 7.5
debian
почти 8 лет назад

memcached version prior to 1.4.37 contains an Integer Overflow vulnera ...

CVSS3: 7.5
github
больше 3 лет назад

memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused from free list. This attack appear to be exploitable via network connectivity to the memcached service. This vulnerability appears to have been fixed in 1.4.37 and later.

CVSS3: 7.5
fstec
почти 8 лет назад

Уязвимость программного средства кэширования данных memcached, связанная с переполнением целых чисел, позволяющая нарушителю вызвать отказ в обслуживании

6.5 Medium

CVSS3