Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10931

Опубликовано: 24 мар. 2020
Источник: redhat
CVSS3: 7.5
EPSS Средний

Описание

Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary protocol header to try_read_command_binary in memcached.c.

A buffer overflow flaw was found in memcached 1.6.0, due to not having a mechanism to verify the length of “extlen” when calling the memcpy function if a large value is assigned to the “extlen” variable. This flaw causes a denial of service and presents a significant risk to system availability.

Отчет

This issue did not affect the versions of memcached as shipped with Red Hat Enterprise Linux 6, 7, and 8 as they did not include the vulnerable code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6memcachedNot affected
Red Hat Enterprise Linux 7memcachedNot affected
Red Hat Enterprise Linux 8memcachedNot affected
Red Hat OpenStack Platform 10 (Newton)memcachedNot affected
Red Hat OpenStack Platform 13 (Queens)memcachedNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=1816630memcached: mishandled memcpy into a stack-based buffer may lead to DoS

EPSS

Процентиль: 98%
0.28144
Средний

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary protocol header to try_read_command_binary in memcached.c.

CVSS3: 7.5
nvd
больше 6 лет назад

Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary protocol header to try_read_command_binary in memcached.c.

CVSS3: 7.5
debian
больше 6 лет назад

Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial ...

github
больше 4 лет назад

Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary protocol header to try_read_command_binary in memcached.c.

EPSS

Процентиль: 98%
0.28144
Средний

7.5 High

CVSS3