|
|
| |
|
| |
memcached: information leak
| Package(s): | memcached |
CVE #(s): | CVE-2009-1255
CVE-2009-1494
|
| Created: | May 4, 2009 |
Updated: | August 11, 2009 |
| Description: |
From the Mandriva advisory:
The process_stat function in Memcached prior 1.2.8 discloses
memory-allocation statistics in response to a stats malloc command,
which allows remote attackers to obtain potentially sensitive
information by sending this command to the daemon's TCP port
(CVE-2009-1255, CVE-2009-1494).
|
| Alerts: |
|
( Log in to post comments)
|
|
|