Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-11596

Опубликовано: 10 апр. 2019
Источник: redhat
CVSS3: 7.5

Описание

In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This causes a denial of service when parsing crafted lru command messages in process_lru_command in memcached.c.

Отчет

The vulnerable code is not present in the versions of memcached as shipped in Red Hat Enterprise Linux 6 and 7, so they are not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6memcachedNot affected
Red Hat Enterprise Linux 7memcachedNot affected
Red Hat OpenStack Platform 10 (Newton)memcachedWill not fix
Red Hat OpenStack Platform 14 (Rocky)memcachedAffected
Red Hat OpenStack Platform 9 (Mitaka)memcachedNot affected
Red Hat Enterprise Linux 8memcachedFixedRHSA-2020:157628.04.2020
Red Hat OpenStack Platform 13.0 (Queens)memcachedFixedRHSA-2020:558316.12.2020
Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUSmemcachedFixedRHSA-2020:558316.12.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1706001memcached: null-pointer dereference in "lru mode" and "lru temp_ttl" causing denial of service

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This causes a denial of service when parsing crafted lru command messages in process_lru_command in memcached.c.

CVSS3: 7.5
nvd
больше 7 лет назад

In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This causes a denial of service when parsing crafted lru command messages in process_lru_command in memcached.c.

CVSS3: 7.5
debian
больше 7 лет назад

In memcached before 1.5.14, a NULL pointer dereference was found in th ...

github
около 4 лет назад

In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This causes a denial of service when parsing crafted lru command messages in process_lru_command in memcached.c.

oracle-oval
больше 6 лет назад

ELSA-2020-1576: memcached security update (MODERATE)

7.5 High

CVSS3