CVE-2018-1000115

Scores

EPSS

0.825high82.5%
0%20%40%60%80%100%

Percentile: 82.5%

CVSS

5.3medium3.x
0246810

CVSS Score: 5.3/10

All CVSS Scores

CVSS 3.x
5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS 2.0
5.0

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Description

Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic amplification of 1:50,000 has been reported by reliable sources). This attack appear to be exploitable via network connectivity to port 11211 UDP. This vulnerability appears to have been fixed in 1.5.6 due to the disabling of the UDP protocol by default.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

debiannvdredhatubuntu

CWEs

CWE-400

Exploits

Exploit ID: 44264

Source: exploitdb

URL: https://www.exploit-db.com/exploits/44264

Exploit ID: 44265

Source: exploitdb

URL: https://www.exploit-db.com/exploits/44265

Recommendations

Source: nvd

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

URL: https://access.redhat.com/errata/RHSA-2018:2857

Source: nvd

For details on how to apply this update, which includes the changesdescribed in this advisory, refer to:
https://access.redhat.com/articles/11258

URL: https://access.redhat.com/errata/RHSA-2018:2331

Source: nvd

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

URL: https://access.redhat.com/errata/RHSA-2018:1627

Source: nvd

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

URL: https://access.redhat.com/errata/RHSA-2018:1593

Source: nvd

Before applying this update, ensure all previously released errata relevantto your system have been applied.
Red Hat OpenStack Platform 9 runs on Red Hat Enterprise Linux 7.4.
The Red Hat OpenStack Platform 9 Release Notes contain the following:
form a working cloud computing environment.
channels need to be enabled and disabled.
The Release Notes are available at:https://access.redhat.com/documentation/en/red-hat-openstack-platform/9/paged/release-notes
This update is available through ‘yum update’ on systems registered throughRed Hat Subscription Manager. For more information about Red HatSubscription Manager, see:
https://access.redhat.com/documentation/en-US/Red_Hat_Subscription_Management/1/html/RHSM/index.html

URL: https://access.redhat.com/errata/RHBA-2018:2140

Vulnerable Software (44)

Type: Configuration

Product: instack-undercloud

Operating System: rhel

Trait:
{  "fixed": "7.4.12-1.el7ost"}

Source: redhat

Type: Configuration

Product: instack-undercloud

Operating System: rhel

Trait:
{  "fixed": "2.2.7-13.el7ost"}

Source: redhat

Type: Configuration

Product: instack-undercloud

Operating System: rhel

Trait:
{  "fixed": "4.0.0-18.el7ost"}

Source: redhat

Type: Configuration

Product: memcached

Operating System: ubuntu artful 17.10

Trait:
{  "fixed": "1.4.33-1ubuntu3.2"}

Source: ubuntu

Type: Configuration

Product: memcached

Operating System: ubuntu trusty 14.04

Trait:
{  "fixed": "1.4.14-0ubuntu9.2"}

Source: ubuntu

Type: Configuration

Product: memcached

Operating System: ubuntu xenial 16.04

Trait:
{  "fixed": "1.4.25-2ubuntu1.3"}

Source: ubuntu

Type: Configuration

Product: memcached

Operating System: altlinux

Trait:
{  "fixed": "0:1.5.6-alt1.S1"}

Source: redhat

Type: Configuration

Product: memcached

Operating System: debian

Trait:
{  "fixed": "1.5.6-1"}

Source: debian

Type: Configuration

Product: memcached

Operating System: debian wheezy 7

Trait:
{  "unfixed": true}

Source: debian

Type: Configuration

Product: memcached-devel

Operating System: altlinux

Trait:
{  "fixed": "0:1.5.6-alt1.S1"}

Source: redhat

Type: Configuration

Product: memcached-tool

Operating System: altlinux

Trait:
{  "fixed": "0:1.5.6-alt1.S1"}

Source: redhat

Type: Configuration

Product: openstack-tripleo-common

Operating System: rhel

Trait:
{  "fixed": "7.6.13-3.el7ost"}

Source: redhat

Type: Configuration

Product: openstack-tripleo-heat-templates

Operating System: rhel

Trait:
{  "fixed": "5.3.10-1.el7ost"}

Source: redhat

Type: Configuration

Product: openstack-tripleo-heat-templates

Operating System: rhel

Trait:
{  "fixed": "6.2.12-2.el7ost"}

Source: redhat

Type: Configuration

Product: openstack-tripleo-heat-templates

Operating System: rhel

Trait:
{  "fixed": "7.0.12-8.el7ost"}

Source: redhat

Type: Configuration

Product: openstack-tripleo-heat-templates

Operating System: rhel

Trait:
{  "fixed": "0.8.14-42.el7ost"}

Source: redhat

Type: Configuration

Product: openstack-tripleo-heat-templates

Operating System: rhel

Trait:
{  "fixed": "2.0.0-65.el7ost"}

Source: redhat

Type: Configuration

Product: openstack-tripleo-image-elements

Operating System: rhel

Trait:
{  "fixed": "7.0.5-1.el7ost"}

Source: redhat

Type: Configuration

Product: openstack-tripleo-puppet-elements

Operating System: rhel

Trait:
{  "fixed": "7.0.7-1.el7ost"}

Source: redhat

Type: Configuration

Product: os-net-config

Operating System: rhel

Trait:
{  "fixed": "7.3.6-1.el7ost"}

Source: redhat