Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2010-1152Improper Input Validation in Memcached

Severity
5.0MEDIUMNVD
EPSS
22.7%
top 4.11%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedApr 12
Latest updateMay 2

Description

memcached.c in memcached before 1.4.3 allows remote attackers to cause a denial of service (daemon hang or crash) via a long line that triggers excessive memory allocation. NOTE: some of these details are obtained from third party information.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/memcached< memcached 1.4.5-1 (bookworm)
Debianmemcached/memcached< 1.4.5-1+3
NVDmemcachedb/memcached1.4.2+19

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jp9p-pjv6-qv68: memcached2022-05-02
OSV
CVE-2010-1152: memcached2010-04-12

💥Exploits & PoCs

1
Exploit-DB
memcached 1.4.2 - Memory Consumption Remote Denial of Service2010-04-27

📋Vendor Advisories

2
Debian
CVE-2010-1152: memcached - memcached.c in memcached before 1.4.3 allows remote attackers to cause a denial ...2010
Red Hat
(v1.2.8): Remote denial of service (excessive memory use, hang / crash)2009-10-27

💬Community

1
Bugzilla
CVE-2010-1152 memcached (v1.2.8): Remote denial of service (excessive memory use, hang / crash)2010-04-10