MEDIUM
memcached: multiple vulnerabilities
Published Apr 30, 2009
5.0
MEDIUMCVSS 2.0
EPSS 2.25%
Description
The process_stat function in (1) Memcached before 1.2.8 and (2) MemcacheDB 1.2.0 discloses (a) the contents of /proc/self/maps in response to a stats maps command and (b) memory-allocation statistics in response to a stats malloc command, which allows remote attackers to obtain sensitive information such as the locations of memory regions, and defeat ASLR protection, by sending a command to the daemon's TCP port.
Affected products
No data.
OR
- ≤ 1.2.0
- 0.0.1
- 0.0.2
- 0.0.3
- 0.0.4
- 0.1.0
- 0.1.1
- 1.0.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
- 1.1.0
- 1.2.0
- 1.2.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (23)
- http://archives.neohapsis.com/archives/fulldisclosure/2009-04/0282.html mailing-listx_refsource_FULLDISC
- http://code.google.com/p/memcachedb/source/browse/trunk/ChangeLog?spec=svn98&r=98 x_refsource_CONFIRM
- http://code.google.com/p/memcachedb/source/detail?r=98 x_refsource_CONFIRM
- http://code.google.com/p/memcachedb/source/diff?spec=svn98&r=98&format=side&path=/trunk/memcachedb.c x_refsource_CONFIRMExploitPatch
- http://groups.google.com/group/memcached/browse_thread/thread/ff96a9b88fb5d40e x_refsource_CONFIRM
- http://osvdb.org/54127 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/34915 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/34932 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/35175 third-party-advisoryx_refsource_SECUNIA
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:105 vendor-advisoryx_refsource_MANDRIVA
- http://www.positronsecurity.com/advisories/2009-001.html x_refsource_MISCExploit
- http://www.securityfocus.com/archive/1/503064/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/34756 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1022140 vdb-entryx_refsource_SECTRACK
- http://www.vupen.com/english/advisories/2009/1196 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2009/1197 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2009-1255 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=498271 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50221 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2009-1255
- https://www.cve.org/CVERecord?id=CVE-2009-1255
- https://www.redhat.com/archives/fedora-package-announce/2009-May/msg00851.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01256.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 30, 2009
Updated Aug 7, 2024
Reserved Apr 7, 2009
Link CVE-2009-1255
CISA Vulnrichment
Updated n/a