1.8
CVSSv2

CVE-2013-7290

Published: 13/01/2014 Updated: 25/03/2018
CVSS v2 Base Score: 1.8 | Impact Score: 2.9 | Exploitability Score: 3.2
VMScore: 160
Vector: AV:A/AC:H/Au:N/C:N/I:N/A:P

Vulnerability Summary

The do_item_get function in items.c in memcached 1.4.4 and other versions prior to 1.4.17, when running in verbose mode, allows remote malicious users to cause a denial of service (segmentation fault) via a request to delete a key, which does not account for the lack of a null terminator in the key and triggers a buffer over-read when printing to stderr, a different vulnerability than CVE-2013-0179.

Vulnerable Product Search on Vulmon Subscribe to Product

memcached memcached 1.4.11

memcached memcached 1.4.12

memcached memcached 1.4.9

memcached memcached 1.4.10

memcached memcached 1.4.4

memcached memcached 1.4.7

memcached memcached 1.4.8

memcached memcached 1.4.15

memcached memcached 1.4.16

memcached memcached 1.4.5

memcached memcached 1.4.6

memcached memcached 1.4.13

memcached memcached 1.4.14

Vendor Advisories

Debian Bug report logs - #735314 memcached: CVE-2013-7291 Package: memcached; Maintainer for memcached is Guillaume Delacour <gui@iroqwaorg>; Source for memcached is src:memcached (PTS, buildd, popcon) Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 14 Jan 2014 15:57:06 UTC Severity: important Tags ...