Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-26635

Опубликовано: 05 апр. 2022
Источник: debian

Описание

PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection. Note: Third parties have disputed this as not affecting PHP-Memcached directly.

Примечания

  • Disputed issue, not considered a security issue by upstream:

  • https://github.com/php-memcached-dev/php-memcached/issues/519#issuecomment-1259303434

  • https://xhzeem.me/posts/Php5-memcached-Injection-Bypass/read/

  • https://github.com/php-memcached-dev/php-memcached/issues/519

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 4 года назад

PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection. Note: Third parties have disputed this as not affecting PHP-Memcached directly.

CVSS3: 9.8
nvd
почти 4 года назад

PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection. Note: Third parties have disputed this as not affecting PHP-Memcached directly.

CVSS3: 9.8
msrc
почти 4 года назад

PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection. Note: Third parties have disputed this as not affecting PHP-Memcached directly.

CVSS3: 9.8
github
почти 4 года назад

PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection.