PT-2018-1892 · Memcached+2 · Memcached+2

Jiejieling

·

Published

2017-07-20

·

Updated

2024-06-15

·

CVE-2018-1000127

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions memcached versions prior to 1.4.37
Description The issue is related to an integer overflow in the memcached data caching software. Exploitation of this issue can be done remotely and may lead to resource leakage, data corruption, deadlock, or crash. The vulnerability is located in the item free() function in items.c and can cause data corruption and deadlocks due to the reuse of items in the hash table from the free list. This attack appears to be exploitable via network connectivity to the memcached service.
Recommendations For memcached versions prior to 1.4.37, update to version 1.4.37 or later to resolve the issue. As a temporary workaround, consider restricting network connectivity to the memcached service to minimize the risk of exploitation.

Fix

Integer Overflow

Improper Locking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1914
BDU:2018-01496
CVE-2018-1000127
DLA-1329-1
DSA-4218-1
OPENSUSE-SU-2024:11045-1
RHSA-2018:2290
USN-3601-1

Affected Products

Alt Linux
Ubuntu
Memcached