CVE-2018-1000127

Related Vulnerabilities: CVE-2018-1000127  

memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused from free list. This attack appear to be exploitable via network connectivity to the memcached service. This vulnerability appears to have been fixed in 1.4.37 and later.

The MITRE CVE dictionary describes this issue as:

memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused from free list. This attack appear to be exploitable via network connectivity to the memcached service. This vulnerability appears to have been fixed in 1.4.37 and later.

Find out more about CVE-2018-1000127 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

CVSS3 Base Score 6.5
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity Impact Low
Availability Impact Low

Red Hat Security Errata

Platform Errata Release Date
Red Hat OpenStack Platform 10 (memcached) RHSA-2018:2290 2018-07-30

Affected Packages State

Platform Package State
Red Hat OpenStack Platform 9.0 memcached Will not fix
Red Hat OpenStack Platform 8.0 (Liberty) memcached Will not fix
Red Hat OpenStack Platform 13.0 (Queens) memcached Not affected
Red Hat OpenStack Platform 12.0 memcached Not affected
Red Hat OpenStack Platform 11.0 (Ocata) memcached Will not fix
Red Hat Mobile Application Platform On-Premise 4 rhmap-memcached-docker Will not fix
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 memcached Will not fix
Red Hat Enterprise Linux 7 memcached Will not fix
Red Hat Enterprise Linux 6 memcached Will not fix