ALT-PU-2017-1914-1
Closed vulnerabilities
BDU:2018-00019
Уязвимость функции try_read_command (memcached.c) программного средства кэширования данных memcached, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2018-01496
Уязвимость программного средства кэширования данных memcached, связанная с переполнением целых чисел, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2017-9951
The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation fault) via a request to add/set a key, which makes a comparison between signed and unsigned int and triggers a heap-based buffer over-read. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8705.
- 99874
- 99874
- https://github.com/memcached/memcached/wiki/ReleaseNotes1439
- https://github.com/memcached/memcached/wiki/ReleaseNotes1439
- https://groups.google.com/forum/message/raw?msg=memcached/ubGWrkmrr4E/nrm1SeVJAQAJ
- https://groups.google.com/forum/message/raw?msg=memcached/ubGWrkmrr4E/nrm1SeVJAQAJ
- USN-3588-1
- USN-3588-1
- DSA-4218
- DSA-4218
- https://www.twistlock.com/2017/07/13/cve-2017-9951-heap-overflow-memcached-server-1-4-38-twistlock-vulnerability-report/
- https://www.twistlock.com/2017/07/13/cve-2017-9951-heap-overflow-memcached-server-1-4-38-twistlock-vulnerability-report/
Modified: 2024-11-21
CVE-2018-1000127
memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused from free list. This attack appear to be exploitable via network connectivity to the memcached service. This vulnerability appears to have been fixed in 1.4.37 and later.
- RHSA-2018:2290
- RHSA-2018:2290
- https://github.com/memcached/memcached/commit/a8c4a82787b8b6c256d61bd5c42fb7f92d1bae00
- https://github.com/memcached/memcached/commit/a8c4a82787b8b6c256d61bd5c42fb7f92d1bae00
- https://github.com/memcached/memcached/issues/271
- https://github.com/memcached/memcached/issues/271
- https://github.com/memcached/memcached/wiki/ReleaseNotes1437
- https://github.com/memcached/memcached/wiki/ReleaseNotes1437
- [debian-lts-announce] 20180329 [SECURITY] [DLA 1329-1] memcached security update
- [debian-lts-announce] 20180329 [SECURITY] [DLA 1329-1] memcached security update
- USN-3601-1
- USN-3601-1
- DSA-4218
- DSA-4218