ALPINE-CVE-2017-9951

Source
https://security.alpinelinux.org/vuln/CVE-2017-9951
Import Source
https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2017-9951.json
JSON Data
https://api.osv.dev/v1/vulns/ALPINE-CVE-2017-9951
Upstream
Published
2017-07-17T13:18:30.970Z
Modified
2025-11-19T06:12:05.984404Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

The tryreadcommand function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation fault) via a request to add/set a key, which makes a comparison between signed and unsigned int and triggers a heap-based buffer over-read. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8705.

References

Affected packages

Alpine:v3.3 / memcached

Package

Name
memcached
Purl
pkg:apk/alpine/memcached?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.33-r1

Affected versions

1.*

1.4.5-r0
1.4.5-r1
1.4.6-r0
1.4.7-r0
1.4.10-r0
1.4.11-r0
1.4.13-r0
1.4.14-r0
1.4.15-r0
1.4.15-r1
1.4.15-r2
1.4.15-r3
1.4.15-r4
1.4.17-r0
1.4.18-r0
1.4.19-r0
1.4.20-r0
1.4.21-r0
1.4.21-r1
1.4.22-r0
1.4.22-r1
1.4.24-r0
1.4.25-r0
1.4.33-r0

Alpine:v3.4 / memcached

Package

Name
memcached
Purl
pkg:apk/alpine/memcached?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.33-r1

Affected versions

1.*

1.4.5-r0
1.4.5-r1
1.4.6-r0
1.4.7-r0
1.4.10-r0
1.4.11-r0
1.4.13-r0
1.4.14-r0
1.4.15-r0
1.4.15-r1
1.4.15-r2
1.4.15-r3
1.4.15-r4
1.4.17-r0
1.4.18-r0
1.4.19-r0
1.4.20-r0
1.4.21-r0
1.4.21-r1
1.4.22-r0
1.4.22-r1
1.4.24-r0
1.4.25-r0
1.4.25-r1
1.4.25-r2
1.4.33-r0

Alpine:v3.5 / memcached

Package

Name
memcached
Purl
pkg:apk/alpine/memcached?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.33-r1

Affected versions

1.*

1.4.5-r0
1.4.5-r1
1.4.6-r0
1.4.7-r0
1.4.10-r0
1.4.11-r0
1.4.13-r0
1.4.14-r0
1.4.15-r0
1.4.15-r1
1.4.15-r2
1.4.15-r3
1.4.15-r4
1.4.17-r0
1.4.18-r0
1.4.19-r0
1.4.20-r0
1.4.21-r0
1.4.21-r1
1.4.22-r0
1.4.22-r1
1.4.24-r0
1.4.25-r0
1.4.25-r1
1.4.25-r2
1.4.31-r0
1.4.32-r0
1.4.33-r0

Alpine:v3.6 / memcached

Package

Name
memcached
Purl
pkg:apk/alpine/memcached?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.36-r1

Affected versions

1.*

1.4.5-r0
1.4.5-r1
1.4.6-r0
1.4.7-r0
1.4.10-r0
1.4.11-r0
1.4.13-r0
1.4.14-r0
1.4.15-r0
1.4.15-r1
1.4.15-r2
1.4.15-r3
1.4.15-r4
1.4.17-r0
1.4.18-r0
1.4.19-r0
1.4.20-r0
1.4.21-r0
1.4.21-r1
1.4.22-r0
1.4.22-r1
1.4.24-r0
1.4.25-r0
1.4.25-r1
1.4.25-r2
1.4.31-r0
1.4.32-r0
1.4.33-r0
1.4.34-r0
1.4.34-r1
1.4.35-r0
1.4.36-r0