{"schema_version":"1.7.5","id":"CVE-2018-1000115","published":"2018-03-05T14:29:00.203Z","modified":"2026-07-08T14:13:22.586676Z","related":["SUSE-RU-2018:1071-1","SUSE-RU-2020:2072-1","SUSE-SU-2018:0955-1","SUSE-SU-2018:1103-1","SUSE-SU-2018:1326-1","openSUSE-SU-2024:11045-1"],"details":"Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic amplification of 1:50,000 has been reported by reliable sources). This attack appear to be exploitable via network connectivity to port 11211 UDP. This vulnerability appears to have been fixed in 1.5.6 due to the disabling of the UDP protocol by default.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/memcached/memcached","events":[{"introduced":"5c0face158f1d0f9c6add22b8f027e468bbe5368"},{"last_affected":"5c0face158f1d0f9c6add22b8f027e468bbe5368"},{"fixed":"dbb7a8af90054bf4ef51f5814ef7ceb17d83d974"}],"database_specific":{"cpe":"cpe:2.3:a:memcached:memcached:1.5.5:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.5.5"},{"last_affected":"1.5.5"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["1.5.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1000115.json","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"193722961698032371527947248956219288832","length":30373},"id":"CVE-2018-1000115-0ac4bbcb","signature_type":"Function","signature_version":"v1","source":"https://github.com/memcached/memcached/commit/dbb7a8af90054bf4ef51f5814ef7ceb17d83d974","target":{"file":"memcached.c","function":"main"}},{"deprecated":false,"digest":{"function_hash":"330998889739120987815784656563466875832","length":1933},"id":"CVE-2018-1000115-9852e524","signature_type":"Function","signature_version":"v1","source":"https://github.com/memcached/memcached/commit/dbb7a8af90054bf4ef51f5814ef7ceb17d83d974","target":{"file":"memcached.c","function":"settings_init"}},{"deprecated":false,"digest":{"line_hashes":["99844338321918568212206164351620081210","61301066329899020218707063201727086268","51627476998667589567435647497634809851","175203149859822716800958277195115406735","226042521575162426575001747920677518870","128900771787833317458517062138927870659","100185069658857430426761737085813262082","203231507774883639279930381864538137391","144245093527256529598901711107644974092","338915189309399925542868337167611278247"],"threshold":0.9},"id":"CVE-2018-1000115-99dc29a1","signature_type":"Line","signature_version":"v1","source":"https://github.com/memcached/memcached/commit/dbb7a8af90054bf4ef51f5814ef7ceb17d83d974","target":{"file":"memcached.c"}}],"vanir_signatures_modified":"2026-07-08T14:13:22Z"}}],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHBA-2018:2140"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:1593"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:1627"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:2331"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:2857"},{"type":"ADVISORY","url":"https://blogs.akamai.com/2018/03/memcached-fueled-13-tbps-attacks.html"},{"type":"ADVISORY","url":"https://github.com/memcached/memcached/wiki/ReleaseNotes156"},{"type":"ADVISORY","url":"https://twitter.com/dormando/status/968579781729009664"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/3588-1/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2018/dsa-4218"},{"type":"ADVISORY","url":"https://www.synology.com/support/security/Synology_SA_18_07"},{"type":"REPORT","url":"https://github.com/memcached/memcached/issues/348"},{"type":"FIX","url":"https://github.com/memcached/memcached/commit/dbb7a8af90054bf4ef51f5814ef7ceb17d83d974"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/44264/"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/44265/"}],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"14.04"},{"last_affected":"14.04"},{"introduced":"16.04"},{"last_affected":"16.04"},{"introduced":"17.10"},{"last_affected":"17.10"}],"source":"CPE_STRING","vendor_product":"canonical:ubuntu_linux"},{"cpes":["cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.0"},{"last_affected":"8.0"},{"introduced":"9.0"},{"last_affected":"9.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux"},{"cpes":["cpe:2.3:a:redhat:openstack:10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openstack:11:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openstack:12:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openstack:8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openstack:9:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8"},{"last_affected":"8"},{"introduced":"9"},{"last_affected":"9"},{"introduced":"10"},{"last_affected":"10"},{"introduced":"11"},{"last_affected":"11"},{"introduced":"12"},{"last_affected":"12"}],"source":"CPE_STRING","vendor_product":"redhat:openstack"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}