5
CVSSv2

CVE-2009-1255

Published: 30/04/2009 Updated: 10/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The process_stat function in (1) Memcached prior to 1.2.8 and (2) MemcacheDB 1.2.0 discloses (a) the contents of /proc/self/maps in response to a stats maps command and (b) memory-allocation statistics in response to a stats malloc command, which allows remote malicious users to obtain sensitive information such as the locations of memory regions, and defeat ASLR protection, by sending a command to the daemon's TCP port.

Vulnerable Product Search on Vulmon Subscribe to Product

memcachedb memcached 1.1.0

memcachedb memcached 1.0.4

memcachedb memcached 0.0.3

memcachedb memcached 0.0.2

memcachedb memcached 1.0.3

memcachedb memcached 1.0.2

memcachedb memcached 0.0.1

memcachedb memcached 1.2.1

memcachedb memcached 1.2.0

memcachedb memcached 0.1.1

memcachedb memcached 0.1.0

memcachedb memcached 0.0.4

memcachedb memcached 1.0.1

memcachedb memcached 1.0.0

memcachedb memcached

Vendor Advisories

Debian Bug report logs - #527330 CVE-2009-1255 affects to memcachedb Package: memcachedb; Maintainer for memcachedb is Arto Jantunen <viiru@debianorg>; Source for memcachedb is src:memcachedb (PTS, buildd, popcon) Reported by: Luciano Bello <luciano@debianorg> Date: Wed, 6 May 2009 21:00:05 UTC Severity: normal T ...