suse · CVE-2017-9951

Quick triage

Priority: critical Published: 2021-05-30 13:57:46 UTC Updated: 2026-04-17 16:06:49 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2017-9951 severity critical: SUSE including 19 source package names (memcached, memcached-1.2.6-5.17.4.1, …), 56 product×package rows across 39 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 4, … (39 product lines)): Fixed 34, Known Not Affected 22.

Description:

The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation fault) via a request to add/set a key, which makes a comparison between signed and unsigned int and triggers a heap-based buffer over-read. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8705.

cvelogic Threat Intelligence