CVE Database
/

CVE-2018-1000115

Back to search

CVE-2018-1000115

Published: Mar 5, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic amplification of 1:50,000 has been reported by reliable sources). This attack appear to be exploitable via network connectivity to port 11211 UDP. This vulnerability appears to have been fixed in 1.5.6 due to the disabling of the UDP protocol by default.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHBA-2018:2140
vendor-advisory
x_refsource_REDHAT
RHSA-2018:1593
vendor-advisory
x_refsource_REDHAT
USN-3588-1
vendor-advisory
x_refsource_UBUNTU
44264
exploit
x_refsource_EXPLOIT-DB
44265
exploit
x_refsource_EXPLOIT-DB
RHSA-2018:2857
vendor-advisory
x_refsource_REDHAT
RHSA-2018:1627
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2331
vendor-advisory
x_refsource_REDHAT
DSA-4218
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now