PT-2023-7069 · Memcached+5 · Memcached+5

Dormando

·

Published

2023-10-27

·

Updated

2024-11-12

·

CVE-2023-46852

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions memcached versions prior to 1.6.22
Description The issue is related to a buffer overflow in the proxy run coroutine() function in memcached, which can be exploited by a remote attacker using a specially crafted HTTP request. This can lead to a denial of service. The buffer overflow occurs when processing multiget requests in proxy mode, specifically if there are many spaces after the "get" substring.
Recommendations For versions prior to 1.6.22, update to version 1.6.22 or later to resolve the issue. As a temporary workaround, consider restricting access to the proxy mode in memcached to minimize the risk of exploitation.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2023-7120
ALT-PU-2023-7210
AZL-31716
AZL-34976
BDU:2023-08094
BIT-MEMCACHED-2023-46852
CVE-2023-46852
OPENSUSE-SU-2024:13427-1
ROSA-SA-2024-2518
USN-6476-1

Affected Products

Alt Linux
Debian
Linuxmint
Red Os
Ubuntu
Memcached