// For flags

CVE-2009-1255

 

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The process_stat function in (1) Memcached before 1.2.8 and (2) MemcacheDB 1.2.0 discloses (a) the contents of /proc/self/maps in response to a stats maps command and (b) memory-allocation statistics in response to a stats malloc command, which allows remote attackers to obtain sensitive information such as the locations of memory regions, and defeat ASLR protection, by sending a command to the daemon's TCP port.

La función process_stat en (1) Memcached antes de v1.2.8 y (2) MemcacheDB v1.2.0 revela (a) el contenido de /proc/self/maps en respuesta a un comando stats maps (estadisticas de mapas) y (b) las estadísticas de la asignación de memoria en respuesta a un comando stats malloc (estadisticas de asignacion de memoria), lo cual permite a atacantes remotos obtener información sensible como la localización de regiones de memoria, y evitar la protección ASLR, mediante el envío de un comando a el demonio del puerto TCP.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-04-07 CVE Reserved
  • 2009-04-28 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Memcachedb
Search vendor "Memcachedb"
Memcached
Search vendor "Memcachedb" for product "Memcached"
<= 1.2.0
Search vendor "Memcachedb" for product "Memcached" and version " <= 1.2.0"
-
Affected
Memcachedb
Search vendor "Memcachedb"
Memcached
Search vendor "Memcachedb" for product "Memcached"
0.0.1
Search vendor "Memcachedb" for product "Memcached" and version "0.0.1"
-
Affected
Memcachedb
Search vendor "Memcachedb"
Memcached
Search vendor "Memcachedb" for product "Memcached"
0.0.2
Search vendor "Memcachedb" for product "Memcached" and version "0.0.2"
-
Affected
Memcachedb
Search vendor "Memcachedb"
Memcached
Search vendor "Memcachedb" for product "Memcached"
0.0.3
Search vendor "Memcachedb" for product "Memcached" and version "0.0.3"
-
Affected
Memcachedb
Search vendor "Memcachedb"
Memcached
Search vendor "Memcachedb" for product "Memcached"
0.0.4
Search vendor "Memcachedb" for product "Memcached" and version "0.0.4"
-
Affected
Memcachedb
Search vendor "Memcachedb"
Memcached
Search vendor "Memcachedb" for product "Memcached"
0.1.0
Search vendor "Memcachedb" for product "Memcached" and version "0.1.0"
-
Affected
Memcachedb
Search vendor "Memcachedb"
Memcached
Search vendor "Memcachedb" for product "Memcached"
0.1.1
Search vendor "Memcachedb" for product "Memcached" and version "0.1.1"
-
Affected
Memcachedb
Search vendor "Memcachedb"
Memcached
Search vendor "Memcachedb" for product "Memcached"
1.0.0
Search vendor "Memcachedb" for product "Memcached" and version "1.0.0"
beta
Affected
Memcachedb
Search vendor "Memcachedb"
Memcached
Search vendor "Memcachedb" for product "Memcached"
1.0.1
Search vendor "Memcachedb" for product "Memcached" and version "1.0.1"
beta
Affected
Memcachedb
Search vendor "Memcachedb"
Memcached
Search vendor "Memcachedb" for product "Memcached"
1.0.2
Search vendor "Memcachedb" for product "Memcached" and version "1.0.2"
beta
Affected
Memcachedb
Search vendor "Memcachedb"
Memcached
Search vendor "Memcachedb" for product "Memcached"
1.0.3
Search vendor "Memcachedb" for product "Memcached" and version "1.0.3"
-
Affected
Memcachedb
Search vendor "Memcachedb"
Memcached
Search vendor "Memcachedb" for product "Memcached"
1.0.4
Search vendor "Memcachedb" for product "Memcached" and version "1.0.4"
-
Affected
Memcachedb
Search vendor "Memcachedb"
Memcached
Search vendor "Memcachedb" for product "Memcached"
1.1.0
Search vendor "Memcachedb" for product "Memcached" and version "1.1.0"
beta
Affected
Memcachedb
Search vendor "Memcachedb"
Memcached
Search vendor "Memcachedb" for product "Memcached"
1.2.0
Search vendor "Memcachedb" for product "Memcached" and version "1.2.0"
beta
Affected
Memcachedb
Search vendor "Memcachedb"
Memcached
Search vendor "Memcachedb" for product "Memcached"
1.2.1
Search vendor "Memcachedb" for product "Memcached" and version "1.2.1"
beta
Affected