CVE-2009-1255: Infoleak
The processstat function in (1) Memcached before 1.2.8 and (2) MemcacheDB 1.2.0 discloses (a) the contents of /proc/self/maps in response to a stats maps command and (b) memory-allocation statistics in response to a stats malloc command, which allows remote attackers to obtain sensitive information such as the locations of memory regions, and defeat ASLR protection, by sending a command to the daemon's TCP port.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1255?
CVE-2009-1255 is classified as a moderate severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2009-1255?
To fix CVE-2009-1255, update to Memcached version 1.2.8 or later, or ensure you're using a non-affected version of MemcacheDB.
What types of information are disclosed by CVE-2009-1255?
CVE-2009-1255 discloses contents from /proc/self/maps and memory-allocation statistics.
Which versions of Memcached are affected by CVE-2009-1255?
CVE-2009-1255 affects Memcached versions prior to 1.2.8.
Is MemcacheDB affected by CVE-2009-1255?
Yes, CVE-2009-1255 affects MemcacheDB versions up to and including 1.2.0.