memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused from free list. This attack appear to be exploitable via network connectivity to the memcached service. This vulnerability appears to have been fixed in 1.4.37 and later.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1329-1 | memcached security update |
Debian DSA |
DSA-4218-1 | memcached security update |
EUVD |
EUVD-2018-1850 | memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused from free list. This attack appear to be exploitable via network connectivity to the memcached service. This vulnerability appears to have been fixed in 1.4.37 and later. |
Ubuntu USN |
USN-3601-1 | Memcached vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T12:33:49.281Z
Reserved: 2018-03-13T00:00:00
Link: CVE-2018-1000127
No data.
Status : Modified
Published: 2018-03-13T21:29:00.477
Modified: 2024-11-21T03:39:44.437
Link: CVE-2018-1000127
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN