CVE-2018-1000127
HIGH7.5EPSS 1.0%memcached - security update
發布日:2018/3/13修改日:2026/4/28
也稱為:DEBIAN-CVE-2018-1000127
描述
memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused from free list. This attack appear to be exploitable via network connectivity to the memcached service. This vulnerability appears to have been fixed in 1.4.37 and later.
受影響套件(2)
- Debian/memcachedfrom 0, < 1.5.0-1
- Debian/memcachedfrom 0, < 1.4.13-0.2+deb7u4
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |