Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-11596

Опубликовано: 10 апр. 2019
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This causes a denial of service when parsing crafted lru command messages in process_lru_command in memcached.c.

Отчет

The vulnerable code is not present in the versions of memcached as shipped in Red Hat Enterprise Linux 6 and 7, so they are not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6memcachedNot affected
Red Hat Enterprise Linux 7memcachedNot affected
Red Hat OpenStack Platform 10 (Newton)memcachedWill not fix
Red Hat OpenStack Platform 14 (Rocky)memcachedAffected
Red Hat OpenStack Platform 9 (Mitaka)memcachedNot affected
Red Hat Enterprise Linux 8memcachedFixedRHSA-2020:157628.04.2020
Red Hat OpenStack Platform 13.0 (Queens)memcachedFixedRHSA-2020:558316.12.2020
Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUSmemcachedFixedRHSA-2020:558316.12.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1706001memcached: null-pointer dereference in "lru mode" and "lru temp_ttl" causing denial of service

EPSS

Процентиль: 82%
0.01644
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 7 лет назад

In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This causes a denial of service when parsing crafted lru command messages in process_lru_command in memcached.c.

CVSS3: 7.5
nvd
почти 7 лет назад

In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This causes a denial of service when parsing crafted lru command messages in process_lru_command in memcached.c.

CVSS3: 7.5
debian
почти 7 лет назад

In memcached before 1.5.14, a NULL pointer dereference was found in th ...

github
больше 3 лет назад

In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This causes a denial of service when parsing crafted lru command messages in process_lru_command in memcached.c.

oracle-oval
почти 6 лет назад

ELSA-2020-1576: memcached security update (MODERATE)

EPSS

Процентиль: 82%
0.01644
Низкий

7.5 High

CVSS3