PT-2018-1892 · Memcached+2 · Memcached+2
Jiejieling
·
Publicado
2017-07-20
·
Atualizado
2024-06-15
·
CVE-2018-1000127
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
memcached versions prior to 1.4.37
Description
The issue is related to an integer overflow in the memcached data caching software. Exploitation of this issue can be done remotely and may lead to resource leakage, data corruption, deadlock, or crash. The vulnerability is located in the
item free() function in items.c and can cause data corruption and deadlocks due to the reuse of items in the hash table from the free list. This attack appears to be exploitable via network connectivity to the memcached service.Recommendations
For memcached versions prior to 1.4.37, update to version 1.4.37 or later to resolve the issue. As a temporary workaround, consider restricting network connectivity to the memcached service to minimize the risk of exploitation.
Correção
Integer Overflow
Improper Locking
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Ubuntu
Memcached