PT-2014-1872 · Memcached+1 · Memcached+1

Jeremy Sowden

·

Publicado

2014-01-13

·

Atualizado

2024-06-15

·

CVE-2013-0179

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions memcached versions 1.4.4 through 1.4.17
Description The issue allows remote attackers to cause a denial of service, potentially leading to disruption of confidentiality, integrity, and availability of protected information. This can be triggered by a request to delete a key, which does not account for the lack of a null terminator in the key and triggers a buffer over-read when printing to stderr. The process bin delete function in memcached.c is specifically affected when running in verbose mode.
Recommendations For memcached versions 1.4.4 through 1.4.17, update to version 1.4.17 or later to resolve the issue. As a temporary workaround, consider disabling verbose mode to minimize the risk of exploitation. Restrict access to the process bin delete function in memcached.c to minimize the risk of disruption.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-2235
BDU:2015-09681
CVE-2013-0179
MGASA-2014-0018
OPENSUSE-SU-2024:10021-1
SUSE-SU-2018:0778-1
SUSE-SU-2018:0807-1

Produtos afetados

Alt Linux
Memcached