First published: Tue Mar 13 2018(Updated: )
A flaw was found in memcached version prior to 1.4.37. It contains an Integer Overflow vulnerability in items.c:item_free() that can result in resource leaks or data corruption, deadlocks and crashes due to items existing in hash table being reused from free list. This attack appear to be exploitable via network connectivity to the memcached service. References: <a href="https://github.com/memcached/memcached/issues/271">https://github.com/memcached/memcached/issues/271</a> <a href="https://github.com/memcached/memcached/wiki/ReleaseNotes1437">https://github.com/memcached/memcached/wiki/ReleaseNotes1437</a> Upstream Patch: <a href="https://github.com/memcached/memcached/commit/a8c4a82787b8b6c256d61bd5c42fb7f92d1bae00">https://github.com/memcached/memcached/commit/a8c4a82787b8b6c256d61bd5c42fb7f92d1bae00</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Memcached Memcached | <1.4.37 | |
Debian Debian Linux | =7.0 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =17.10 | |
Redhat Openstack | =10 | |
redhat/memcached | <1.4.37 | 1.4.37 |
ubuntu/memcached | <1.4.33-1ubuntu3.3 | 1.4.33-1ubuntu3.3 |
ubuntu/memcached | <1.4.14-0ubuntu9.3 | 1.4.14-0ubuntu9.3 |
ubuntu/memcached | <1.5.0-1 | 1.5.0-1 |
ubuntu/memcached | <1.4.25-2ubuntu1.4 | 1.4.25-2ubuntu1.4 |
debian/memcached | 1.6.9+dfsg-1 1.6.18-1 1.6.29-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000127 is a vulnerability in memcached version prior to 1.4.37 that can result in data corruption and deadlocks.
CVE-2018-1000127 has a severity level of 7.5 (high).
The software affected by CVE-2018-1000127 is memcached version prior to 1.4.37.
To fix CVE-2018-1000127, upgrade to memcached version 1.4.37 or higher.
You can find more information about CVE-2018-1000127 on the Debian security tracker and MITRE's CVE database.