Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10931

Опубликовано: 24 мар. 2020
Источник: redhat
CVSS3: 7.5

Описание

Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary protocol header to try_read_command_binary in memcached.c.

A buffer overflow flaw was found in memcached 1.6.0, due to not having a mechanism to verify the length of “extlen” when calling the memcpy function if a large value is assigned to the “extlen” variable. This flaw causes a denial of service and presents a significant risk to system availability.

Отчет

This issue did not affect the versions of memcached as shipped with Red Hat Enterprise Linux 6, 7, and 8 as they did not include the vulnerable code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6memcachedNot affected
Red Hat Enterprise Linux 7memcachedNot affected
Red Hat Enterprise Linux 8memcachedNot affected
Red Hat OpenStack Platform 10 (Newton)memcachedNot affected
Red Hat OpenStack Platform 13 (Queens)memcachedNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=1816630memcached: mishandled memcpy into a stack-based buffer may lead to DoS

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary protocol header to try_read_command_binary in memcached.c.

CVSS3: 7.5
nvd
почти 6 лет назад

Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary protocol header to try_read_command_binary in memcached.c.

CVSS3: 7.5
debian
почти 6 лет назад

Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial ...

github
больше 3 лет назад

Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary protocol header to try_read_command_binary in memcached.c.

7.5 High

CVSS3