CVE-2009-2415
published 2009-08-10CVE-2009-2415: Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers to execute arbitrary code via vectors involving length attributes that trigger…
PriorityP346critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.62%
93.1th percentile
Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers to execute arbitrary code via vectors involving length attributes that trigger heap-based buffer overflows.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | memcached | < memcached 1.4.1-1 (bookworm) | memcached 1.4.1-1 (bookworm) |
| memcached | memcached | >= 0 < 1.4.1-1 | 1.4.1-1 |
| memcached | memcached | >= 0 < 1.4.1-1 | 1.4.1-1 |
| memcached | memcached | >= 0 < 1.4.1-1 | 1.4.1-1 |
| memcached | memcached | >= 0 < 1.4.1-1 | 1.4.1-1 |
| memcachedb | memcached | — | — |
| memcachedb | memcached | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0MEDIUM
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4r9m-gmj4-v54c: Multiple integer overflows in memcached 1
ghsa_unreviewed·2022-05-02
CVE-2009-2415 [HIGH] GHSA-4r9m-gmj4-v54c: Multiple integer overflows in memcached 1
Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers to execute arbitrary code via vectors involving length attributes that trigger heap-based buffer overflows.
OSV
CVE-2009-2415: Multiple integer overflows in memcached 1
osv·2009-08-10·CVSS 10.0
CVE-2009-2415 [CRITICAL] CVE-2009-2415: Multiple integer overflows in memcached 1
Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers to execute arbitrary code via vectors involving length attributes that trigger heap-based buffer overflows.
Debian
CVE-2009-2415: memcached - Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers ...
vendor_debian·2009·CVSS 10.0
CVE-2009-2415 [CRITICAL] CVE-2009-2415: memcached - Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers ...
Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers to execute arbitrary code via vectors involving length attributes that trigger heap-based buffer overflows.
Scope: local
bookworm: resolved (fixed in 1.4.1-1)
bullseye: resolved (fixed in 1.4.1-1)
forky: resolved (fixed in 1.4.1-1)
sid: resolved (fixed in 1.4.1-1)
trixie: resolved (fixed in 1.4.1-1)
Red Hat
memcached: heap-based buffer overflow
vendor_redhat·CVSS 10.0
CVE-2009-2415 [CRITICAL] memcached: heap-based buffer overflow
memcached: heap-based buffer overflow
Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers to execute arbitrary code via vectors involving length attributes that trigger heap-based buffer overflows.
No detection rules found.
No public exploits indexed.
http://osvdb.org/56906http://secunia.com/advisories/36133http://secunia.com/advisories/37729http://security.debian.org/pool/updates/main/m/memcached/memcached_1.1.12-1+etch1.diff.gzhttp://security.debian.org/pool/updates/main/m/memcached/memcached_1.2.2-1+lenny1.diff.gzhttp://www.debian.org/security/2009/dsa-1853http://www.securityfocus.com/bid/35989https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00836.htmlhttp://osvdb.org/56906http://secunia.com/advisories/36133http://secunia.com/advisories/37729http://security.debian.org/pool/updates/main/m/memcached/memcached_1.1.12-1+etch1.diff.gzhttp://security.debian.org/pool/updates/main/m/memcached/memcached_1.2.2-1+lenny1.diff.gzhttp://www.debian.org/security/2009/dsa-1853http://www.securityfocus.com/bid/35989https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00836.html
2009-08-10
Published