Impact
A heap-based buffer overflow flaw exists in the APR memcached client. The client incorrectly handles certain packet sizes, allowing an attacker to overflow the heap allocation and overwrite control data. If the overflow is successful, the attacker can gain arbitrary code execution on the affected system. The nature of the vulnerability, as identified by CWE-120 and CWE-122, indicates that memory corruption could lead to a full compromise.
Affected Systems
Apache Portable Runtime Utility of the Apache Software Foundation is affected, specifically versions 1.3.0 through 1.6.3. No other products or versions are listed as impacted.
Risk and Exploitability
The vulnerability has an EPSS score of < 1% (approximately 0.00528), indicating a very low exploitation probability, yet the lack of visibility does not diminish the potential risk. The flaw is exploitable by any actor who can send crafted memcached messages to the APR memcached client, which may be exposed either locally or over a network. The exact attack vector is not documented in the description, but the use of a memcached client strongly suggests that a remote attacker could trigger the overflow if the service is reachable. The CVSS score for this vulnerability is 7.5.
OpenCVE Enrichment
Debian DLA
Debian DSA