5
CVSSv2

CVE-2010-1152

Published: 12/04/2010 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

memcached.c in memcached prior to 1.4.3 allows remote malicious users to cause a denial of service (daemon hang or crash) via a long line that triggers excessive memory allocation. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

memcachedb memcached 1.0.0

memcachedb memcached 1.2.1

memcachedb memcached 1.0.4

memcachedb memcached 1.2.8

memcachedb memcached 1.2.2

memcachedb memcached 1.0.3

memcachedb memcached 1.4.1

memcachedb memcached 0.0.3

memcachedb memcached 1.1.0

memcachedb memcached 0.1.1

memcachedb memcached 1.0.1

memcachedb memcached 0.1.0

memcachedb memcached 1.2.0

memcachedb memcached 1.1.12

memcachedb memcached 0.0.2

memcachedb memcached 1.4.0

memcachedb memcached 1.0.2

memcachedb memcached 0.0.4

memcachedb memcached

memcachedb memcached 0.0.1

Vendor Advisories

Debian Bug report logs - #579913 CVE-2010-1152: denial of service (daemon hang or crash) Package: memcached; Maintainer for memcached is Guillaume Delacour <gui@iroqwaorg>; Source for memcached is src:memcached (PTS, buildd, popcon) Reported by: Giuseppe Iuculano <iuculano@debianorg> Date: Sun, 2 May 2010 09:33:02 ...

Exploits

source: wwwsecurityfocuscom/bid/39577/info memcached is prone to a remote denial-of-service vulnerability An attacker can exploit this issue to cause the application to allocate large amount of memory, hanging or crashing the application memcached versions prior to 143 are affected cat /dev/zero | nc -q1 127001 11211 ...