MEDIUM
memcached: multiple vulnerabilities
Published Apr 30, 2009
5.0
MEDIUMCVSS 2.0
EPSS 1.49%
Description
The process_stat function in Memcached 1.2.8 discloses memory-allocation statistics in response to a stats malloc command, which allows remote attackers to obtain potentially sensitive information by sending this command to the daemon's TCP port.
Affected products
No data.
- 1.2.8
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (11)
- http://code.google.com/p/memcachedb/source/browse/trunk/ChangeLog?spec=svn98&r=98 x_refsource_MISC
- http://code.google.com/p/memcachedb/source/detail?r=98 x_refsource_MISCPatch
- http://code.google.com/p/memcachedb/source/diff?spec=svn98&r=98&format=side&path=/trunk/memcachedb.c x_refsource_MISCPatch
- http://groups.google.com/group/memcached/browse_thread/thread/ff96a9b88fb5d40e x_refsource_MISCPatch
- http://memcached.googlecode.com/files/memcached-1.2.8.tar.gz x_refsource_MISC
- https://access.redhat.com/security/cve/CVE-2009-1494 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=498271 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-1491 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50444 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2009-1494
- https://www.cve.org/CVERecord?id=CVE-2009-1494
| Link | Providers | Tags |
|---|---|---|
| http://code.google.com/p/memcachedb/source/browse/trunk/ChangeLog?spec=svn98&r=98 | x_refsource_MISC | |
| http://code.google.com/p/memcachedb/source/detail?r=98 | x_refsource_MISCPatch | |
| http://code.google.com/p/memcachedb/source/diff?spec=svn98&r=98&format=side&path=/trunk/memcachedb.c | x_refsource_MISCPatch | |
| http://groups.google.com/group/memcached/browse_thread/thread/ff96a9b88fb5d40e | x_refsource_MISCPatch | |
| http://memcached.googlecode.com/files/memcached-1.2.8.tar.gz | x_refsource_MISC | |
| https://access.redhat.com/security/cve/CVE-2009-1494 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=498271 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-1491 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/50444 | vdb-entryx_refsource_XF | |
| https://nvd.nist.gov/vuln/detail/CVE-2009-1494 | ||
| https://www.cve.org/CVERecord?id=CVE-2009-1494 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 30, 2009
Updated Aug 7, 2024
Reserved Apr 30, 2009
Link CVE-2009-1494
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2009-1491 Assigner mitre
Published Apr 30, 2009
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2009-1491