Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-7290

Опубликовано: 13 янв. 2014
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 1.8

Описание

The do_item_get function in items.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (segmentation fault) via a request to delete a key, which does not account for the lack of a null terminator in the key and triggers a buffer over-read when printing to stderr, a different vulnerability than CVE-2013-0179.

РелизСтатусПримечание
devel

not-affected

1.4.14-0ubuntu9
lucid

ignored

end of life
precise

not-affected

1.4.13-0ubuntu2.1
quantal

not-affected

1.4.14-0ubuntu1.12.10.1
raring

not-affected

1.4.14-0ubuntu1.13.04.1
saucy

not-affected

1.4.14-0ubuntu4.1
upstream

needs-triage

Показывать по

Ссылки на источники

EPSS

Процентиль: 43%
0.00207
Низкий

1.8 Low

CVSS2

Связанные уязвимости

redhat
около 13 лет назад

The do_item_get function in items.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (segmentation fault) via a request to delete a key, which does not account for the lack of a null terminator in the key and triggers a buffer over-read when printing to stderr, a different vulnerability than CVE-2013-0179.

nvd
около 12 лет назад

The do_item_get function in items.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (segmentation fault) via a request to delete a key, which does not account for the lack of a null terminator in the key and triggers a buffer over-read when printing to stderr, a different vulnerability than CVE-2013-0179.

debian
около 12 лет назад

The do_item_get function in items.c in memcached 1.4.4 and other versi ...

github
больше 3 лет назад

The do_item_get function in items.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (segmentation fault) via a request to delete a key, which does not account for the lack of a null terminator in the key and triggers a buffer over-read when printing to stderr, a different vulnerability than CVE-2013-0179.

fstec
больше 11 лет назад

Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 43%
0.00207
Низкий

1.8 Low

CVSS2