CVE-2018-1000115
Last modified
CVE-2018-1000115 is a vulnerability of currently unknown severity. Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic amplification of 1:50,000 has been reported by reliable sources). This attack appear to be exploitable via network connectivity to port 11211 UDP. EPSS estimates a 88.64% chance of exploitation in the next 30 days.
Description
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic amplification of 1:50,000 has been reported by reliable sources). This attack appear to be exploitable via network connectivity to port 11211 UDP. This vulnerability appears to have been fixed in 1.5.6 due to the disabling of the UDP protocol by default.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Memcached | Memcached | 1.5.5 |
| Canonical | Ubuntu Linux | 14.04 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 17.10 |
| Debian | Debian Linux | 8.0 |
| Debian | Debian Linux | 9.0 |
| Redhat | Openstack | 8 |
| Redhat | Openstack | 9 |
| Redhat | Openstack | 10 |
| Redhat | Openstack | 11 |
| Redhat | Openstack | 12 |
References
- https://access.redhat.com/errata/RHBA-2018:2140Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1593Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1627Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2331Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2857Third Party Advisory
- https://blogs.akamai.com/2018/03/memcached-fueled-13-tbps-attacks.htmlThird Party Advisory
- https://github.com/memcached/memcached/commit/dbb7a8af90054bf4ef51f5814ef7ceb17d83d974Patch, Third Party Advisory
- https://github.com/memcached/memcached/issues/348Issue Tracking, Third Party Advisory
- https://github.com/memcached/memcached/wiki/ReleaseNotes156Third Party Advisory
- https://twitter.com/dormando/status/968579781729009664Third Party Advisory
- https://usn.ubuntu.com/3588-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4218Third Party Advisory
- https://www.exploit-db.com/exploits/44264/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/44265/Exploit, Third Party Advisory, VDB Entry
- https://www.synology.com/support/security/Synology_SA_18_07Third Party Advisory
- https://access.redhat.com/errata/RHBA-2018:2140Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1593Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1627Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2331Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2857Third Party Advisory
- https://blogs.akamai.com/2018/03/memcached-fueled-13-tbps-attacks.htmlThird Party Advisory
- https://github.com/memcached/memcached/commit/dbb7a8af90054bf4ef51f5814ef7ceb17d83d974Patch, Third Party Advisory
- https://github.com/memcached/memcached/issues/348Issue Tracking, Third Party Advisory
- https://github.com/memcached/memcached/wiki/ReleaseNotes156Third Party Advisory
- https://twitter.com/dormando/status/968579781729009664Third Party Advisory
- https://usn.ubuntu.com/3588-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4218Third Party Advisory
- https://www.exploit-db.com/exploits/44264/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/44265/Exploit, Third Party Advisory, VDB Entry
- https://www.synology.com/support/security/Synology_SA_18_07Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-1000115?
How severe is CVE-2018-1000115?
How do I fix CVE-2018-1000115?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-1000109An improper authorization vulnerability exists in Jenkins Go…
- CVE-2018-1000110An improper authorization vulnerability exists in Jenkins Gi…
- CVE-2018-1000111An improper authorization vulnerability exists in Jenkins Su…
- CVE-2018-1000112An improper authorization vulnerability exists in Jenkins Me…
- CVE-2018-1000113A cross-site scripting vulnerability exists in Jenkins TestL…
- CVE-2018-1000114An improper authorization vulnerability exists in Jenkins Pr…
- CVE-2018-1000116NET-SNMP version 5.7.2 contains a heap corruption vulnerabil…
- CVE-2018-1000117Python Software Foundation CPython version From 3.2 until 3.…6.7
- CVE-2018-1000118Github Electron version Electron 1.8.2-beta.4 and earlier co…
- CVE-2018-1000119Sinatra rack-protection versions 1.5.4 and 2.0.0.rc3 and ear…
- CVE-2018-1000120A buffer overflow exists in curl 7.12.3 to and including cur…
- CVE-2018-1000121A NULL pointer dereference exists in curl 7.21.0 to and incl…
Are you affected by CVE-2018-1000115?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
