5

CVE-2011-4971

Exploit

Multiple integer signedness errors in the (1) process_bin_sasl_auth, (2) process_bin_complete_sasl_auth, (3) process_bin_update, and (4) process_bin_append_prepend functions in Memcached 1.4.5 and earlier allow remote attackers to cause a denial of service (crash) via a large body length value in a packet.

Data is provided by the National Vulnerability Database (NVD)
MemcachedMemcached Version <= 1.4.5
MemcachedMemcached Version1.2.7
MemcachedMemcached Version1.2.8
MemcachedMemcached Version1.4.0
MemcachedMemcached Version1.4.1
MemcachedMemcached Version1.4.2
MemcachedMemcached Version1.4.3
MemcachedMemcached Version1.4.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 53.16% 0.979
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P