PT-2018-1892 · Memcached+2 · Memcached+2

Jiejieling

·

Publicado

2017-07-20

·

Atualizado

2024-06-15

·

CVE-2018-1000127

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions memcached versions prior to 1.4.37
Description The issue is related to an integer overflow in the memcached data caching software. Exploitation of this issue can be done remotely and may lead to resource leakage, data corruption, deadlock, or crash. The vulnerability is located in the item free() function in items.c and can cause data corruption and deadlocks due to the reuse of items in the hash table from the free list. This attack appears to be exploitable via network connectivity to the memcached service.
Recommendations For memcached versions prior to 1.4.37, update to version 1.4.37 or later to resolve the issue. As a temporary workaround, consider restricting network connectivity to the memcached service to minimize the risk of exploitation.

Correção

Integer Overflow

Improper Locking

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1914
BDU:2018-01496
CVE-2018-1000127
DLA-1329-1
DSA-4218-1
OPENSUSE-SU-2024:11045-1
RHSA-2018:2290
USN-3601-1

Produtos afetados

Alt Linux
Ubuntu
Memcached