Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.64630
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-1853-1)
Summary:The remote host is missing an update for the Debian 'memcached' package(s) announced via the DSA-1853-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'memcached' package(s) announced via the DSA-1853-1 advisory.

Vulnerability Insight:
Ronald Volgers discovered that memcached, a high-performance memory object caching system, is vulnerable to several heap-based buffer overflows due to integer conversions when parsing certain length attributes. An attacker can use this to execute arbitrary code on the system running memcached (on etch with root privileges).

For the oldstable distribution (etch), this problem has been fixed in version 1.1.12-1+etch1.

For the stable distribution (lenny), this problem has been fixed in version 1.2.2-1+lenny1.

For the testing (squeeze) and unstable (sid) distribution, this problem will be fixed soon.

We recommend that you upgrade your memcached packages.

Affected Software/OS:
'memcached' package(s) on Debian 4, Debian 5.

Solution:
Please install the updated package(s).

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-2415
35989
http://www.securityfocus.com/bid/35989
36133
http://secunia.com/advisories/36133
37729
http://secunia.com/advisories/37729
56906
http://osvdb.org/56906
DSA-1853
http://www.debian.org/security/2009/dsa-1853
FEDORA-2009-12552
https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00836.html
http://security.debian.org/pool/updates/main/m/memcached/memcached_1.1.12-1+etch1.diff.gz
http://security.debian.org/pool/updates/main/m/memcached/memcached_1.2.2-1+lenny1.diff.gz
CopyrightCopyright (C) 2009 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.