Back

MEDIUM

memcached: multiple vulnerabilities

Published Apr 30, 2009

Description

The process_stat function in (1) Memcached before 1.2.8 and (2) MemcacheDB 1.2.0 discloses (a) the contents of /proc/self/maps in response to a stats maps command and (b) memory-allocation statistics in response to a stats malloc command, which allows remote attackers to obtain sensitive information such as the locations of memory regions, and defeat ASLR protection, by sending a command to the daemon's TCP port.

Affected products

Remediation

No remediation recorded yet.

References (23)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 30, 2009
Updated Aug 7, 2024
Reserved Apr 7, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Apr 28, 2009