Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-22570

Опубликовано: 22 авг. 2023
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command.

A vulnerability was found in Memcached. This security issue appears as a NULL pointer dereference vulnerability in memcached.c that allows remote attackers to cause a denial of service (daemon crash) via a crafted meta-command.

Отчет

This issue does not affect Red Hat Enterprise Linux 6, 7, 8 and 9 as the affected version of memcached package is currently not provided in any of our supported products.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6memcachedNot affected
Red Hat Enterprise Linux 7memcachedNot affected
Red Hat Enterprise Linux 8memcachedNot affected
Red Hat Enterprise Linux 9memcachedNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=2234997memcached: NULL pointer dereference in process_mget_command function in memcached.c

EPSS

Процентиль: 84%
0.02068
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command.

CVSS3: 7.5
nvd
больше 2 лет назад

Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command.

CVSS3: 7.5
debian
больше 2 лет назад

Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial ...

CVSS3: 7.5
github
больше 2 лет назад

Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command.

EPSS

Процентиль: 84%
0.02068
Низкий

6.5 Medium

CVSS3