Vulnerability CVE-2009-2415


Published: 2009-08-10   Modified: 2012-02-13

Description:
Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers to execute arbitrary code via vectors involving length attributes that trigger heap-based buffer overflows.

Type:

CWE-189

(Numeric Errors)

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Memcachedb -> Memcached 

 References:
https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00836.html
http://www.securityfocus.com/bid/35989
http://www.debian.org/security/2009/dsa-1853
http://security.debian.org/pool/updates/main/m/memcached/memcached_1.2.2-1+lenny1.diff.gz
http://security.debian.org/pool/updates/main/m/memcached/memcached_1.1.12-1+etch1.diff.gz
http://secunia.com/advisories/37729
http://secunia.com/advisories/36133
http://osvdb.org/56906

Copyright 2024, cxsecurity.com

 

Back to Top