PT-2019-4903 · Memcached+4 · Memcached+4

Tomas Korbar

·

Published

2019-08-30

·

Updated

2021-02-04

·

CVE-2019-15026

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions memcached version 1.5.16
Description The issue is related to a stack-based buffer over-read in the conn to str function in memcached.c. This can be exploited by a remote attacker to cause a denial of service.
Recommendations For memcached version 1.5.16, consider disabling the use of UNIX sockets as a temporary workaround until a patch is available. Restrict access to the conn to str function in memcached.c to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2674
ALT-PU-2019-2894
BDU:2020-01500
CVE-2019-15026
DLA-1913-1
MGASA-2020-0016
OESA-2021-1006
OPENSUSE-SU-2020:0721-1
OPENSUSE-SU-2020_0721-1
SUSE-RU-2020:2072-1
SUSE-SU-2020:0843-1
SUSE-SU-2020:1066-1
SUSE-SU-2020:1190-1
SUSE-SU-2020:1381-1
USN-4125-1

Affected Products

Alt Linux
Astra Linux
Suse
Ubuntu
Memcached