The process_stat function in Memcached 1.2.8 discloses memory-allocation statistics in...
Vulnerability Description
The process_stat function in Memcached 1.2.8 discloses memory-allocation statistics in response to a stats malloc command, which allows remote attackers to obtain potentially sensitive information by sending this command to the daemon's TCP port.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-1494
Credits & Attribution
No credits recorded in the NVD database.
References
- http://code.google.com/p/memcachedb/source/browse/trunk/ChangeLog?spec=svn98&r=98
- http://memcached.googlecode.com/files/memcached-1.2.8.tar.gz
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50444
- http://code.google.com/p/memcachedb/source/detail?r=98
- http://code.google.com/p/memcachedb/source/diff?spec=svn98&r=98&format=side&path=/trunk/memcachedb.c
- http://groups.google.com/group/memcached/browse_thread/thread/ff96a9b88fb5d40e
More from memcachedb
View All →Affected Vendor
memcachedb
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.