5

CVE-2010-1152

Exploit
memcached.c in memcached before 1.4.3 allows remote attackers to cause a denial of service (daemon hang or crash) via a long line that triggers excessive memory allocation.  NOTE: some of these details are obtained from third party information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MemcachedbMemcached Version <= 1.4.2
MemcachedbMemcached Version0.0.1
MemcachedbMemcached Version0.0.2
MemcachedbMemcached Version0.0.3
MemcachedbMemcached Version0.0.4
MemcachedbMemcached Version0.1.0
MemcachedbMemcached Version0.1.1
MemcachedbMemcached Version1.0.0 Updatebeta
MemcachedbMemcached Version1.0.1 Updatebeta
MemcachedbMemcached Version1.0.2 Updatebeta
MemcachedbMemcached Version1.0.3
MemcachedbMemcached Version1.0.4
MemcachedbMemcached Version1.1.0 Updatebeta
MemcachedbMemcached Version1.1.12
MemcachedbMemcached Version1.2.0
MemcachedbMemcached Version1.2.0 Updatebeta
MemcachedbMemcached Version1.2.1 Updatebeta
MemcachedbMemcached Version1.2.2
MemcachedbMemcached Version1.2.8
MemcachedbMemcached Version1.4.0
MemcachedbMemcached Version1.4.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 10.44% 0.952
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html
http://blogs.sun.com/security/entry/input_validation_vulnerability_in_memcached
http://code.google.com/p/memcached/issues/detail?id=102
Exploit
http://github.com/memcached/memcached/commit/75cc83685e103bc8ba380a57468c8f04413033f9
Patch
http://github.com/memcached/memcached/commit/d9cd01ede97f4145af9781d448c62a3318952719
Patch
http://marc.info/?l=oss-security&m=127074597129559&w=2
Patch
http://marc.info/?l=oss-security&m=127075341110616&w=2
Patch
http://marc.info/?l=oss-security&m=127075808518733&w=2
Patch
http://secunia.com/advisories/39306
Vendor Advisory
http://securitytracker.com/id?1023839
http://www.vupen.com/english/advisories/2011/0442