PT-2014-1872 · Memcached+1 · Memcached+1

Jeremy Sowden

·

Published

2014-01-13

·

Updated

2024-06-15

·

CVE-2013-0179

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions memcached versions 1.4.4 through 1.4.17
Description The issue allows remote attackers to cause a denial of service, potentially leading to disruption of confidentiality, integrity, and availability of protected information. This can be triggered by a request to delete a key, which does not account for the lack of a null terminator in the key and triggers a buffer over-read when printing to stderr. The process bin delete function in memcached.c is specifically affected when running in verbose mode.
Recommendations For memcached versions 1.4.4 through 1.4.17, update to version 1.4.17 or later to resolve the issue. As a temporary workaround, consider disabling verbose mode to minimize the risk of exploitation. Restrict access to the process bin delete function in memcached.c to minimize the risk of disruption.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2235
BDU:2015-09681
CVE-2013-0179
MGASA-2014-0018
OPENSUSE-SU-2024:10021-1
SUSE-SU-2018:0778-1
SUSE-SU-2018:0807-1

Affected Products

Alt Linux
Memcached