Vulnerability Description
memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused from free list. This attack appear to be exploitable via network connectivity to the memcached service. This vulnerability appears to have been fixed in 1.4.37 and later.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Memcached | Memcached | < 1.4.37 |
| Debian | Debian Linux | 7.0 |
| Canonical | Ubuntu Linux | 14.04 |
| Redhat | Openstack | 10 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2018:2290Third Party Advisory
- https://github.com/memcached/memcached/commit/a8c4a82787b8b6c256d61bd5c42fb7f92dPatchThird Party Advisory
- https://github.com/memcached/memcached/issues/271Third Party Advisory
- https://github.com/memcached/memcached/wiki/ReleaseNotes1437Release NotesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/03/msg00031.htmlMailing ListThird Party Advisory
- https://usn.ubuntu.com/3601-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4218Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2290Third Party Advisory
- https://github.com/memcached/memcached/commit/a8c4a82787b8b6c256d61bd5c42fb7f92dPatchThird Party Advisory
- https://github.com/memcached/memcached/issues/271Third Party Advisory
- https://github.com/memcached/memcached/wiki/ReleaseNotes1437Release NotesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/03/msg00031.htmlMailing ListThird Party Advisory
- https://usn.ubuntu.com/3601-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4218Third Party Advisory
FAQ
What is CVE-2018-1000127?
CVE-2018-1000127 is a vulnerability with a CVSS score of 7.5 (HIGH). memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused fr...
How severe is CVE-2018-1000127?
CVE-2018-1000127 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-1000127?
Check the references section above for vendor advisories and patch information. Affected products include: Memcached Memcached, Debian Debian Linux, Canonical Ubuntu Linux, Redhat Openstack.