CVE-2018-1000127
Summary
| CVE | CVE-2018-1000127 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-13 21:29:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused from free list. This attack appear to be exploitable via network connectivity to the memcached service. This vulnerability appears to have been fixed in 1.4.37 and later. |
Risk And Classification
Problem Types: CWE-190 | CWE-667
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 17.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 17.10 | All | All | All |
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Application | Memcached | Memcached | All | All | All | All |
| Application | Memcached | Memcached | All | All | All | All |
| Application | Redhat | Openstack | 10 | All | All | All |
| Application | Redhat | Openstack | 10 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ReleaseNotes1437 · memcached/memcached Wiki · GitHub | CONFIRM | github.com | Release Notes, Third Party Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | Third Party Advisory |
| Don't overflow item refcount on get · memcached/memcached@a8c4a82 · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| Debian -- Security Information -- DSA-4218-1 memcached | DEBIAN | www.debian.org | Third Party Advisory |
| Memcached gets a dead loop in func assoc_find · Issue #271 · memcached/memcached · GitHub | CONFIRM | github.com | Third Party Advisory |
| [SECURITY] [DLA 1329-1] memcached security update | MLIST | lists.debian.org | Mailing List, Third Party Advisory |
| USN-3601-1: Memcached vulnerability | Ubuntu security notices | UBUNTU | usn.ubuntu.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.