High severity7.5NVD Advisory· Published Jul 17, 2017· Updated May 13, 2026
CVE-2017-9951
CVE-2017-9951
Description
The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation fault) via a request to add/set a key, which makes a comparison between signed and unsigned int and triggers a heap-based buffer over-read. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8705.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.twistlock.com/2017/07/13/cve-2017-9951-heap-overflow-memcached-server-1-4-38-twistlock-vulnerability-report/nvdExploitTechnical DescriptionThird Party Advisory
- groups.google.com/forum/message/rawnvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/99874nvd
- usn.ubuntu.com/3588-1/nvd
- www.debian.org/security/2018/dsa-4218nvd
News mentions
0No linked articles in our index yet.