Описание
A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file proto_text.c of the component mcmc Tokenizer. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.6.44 is able to resolve this issue. The patch is identified as af05c9302bba508b736c3da1d5670f63fe8b7db4. You should upgrade the affected component.
A flaw was found in memcached. A remote attacker could exploit an out-of-bounds read vulnerability in the try_read_command_asciiauth function. This could lead to a Denial of Service (DoS) condition, making the service unavailable to legitimate users.
Меры по смягчению последствий
To reduce exposure, restrict network access to the memcached service. Configure memcached to listen only on trusted interfaces or localhost, preventing remote attackers from reaching the vulnerable component. For example, modify the memcached service configuration to bind to 127.0.0.1 or a specific internal IP address. A service restart is required for changes to take effect and may temporarily impact services utilizing memcached.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | memcached | Not affected | ||
| Red Hat Enterprise Linux 10 | rhel10/memcached | Not affected | ||
| Red Hat Enterprise Linux 6 | memcached | Not affected | ||
| Red Hat Enterprise Linux 7 | memcached | Not affected | ||
| Red Hat Enterprise Linux 8 | memcached | Not affected | ||
| Red Hat Enterprise Linux 9 | memcached | Not affected | ||
| Red Hat Enterprise Linux 9 | rhel9/memcached | Not affected | ||
| Red Hat Hardened Images | memcached | Affected | ||
| Red Hat OpenStack Platform 13 (Queens) | memcached | Not affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file proto_text.c of the component mcmc Tokenizer. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.6.44 is able to resolve this issue. The patch is identified as af05c9302bba508b736c3da1d5670f63fe8b7db4. You should upgrade the affected component.
A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file proto_text.c of the component mcmc Tokenizer. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.6.44 is able to resolve this issue. The patch is identified as af05c9302bba508b736c3da1d5670f63fe8b7db4. You should upgrade the affected component.
A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. ...
A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file proto_text.c of the component mcmc Tokenizer. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.6.44 is able to resolve this issue. The patch is identified as af05c9302bba508b736c3da1d5670f63fe8b7db4. You should upgrade the affected component.
EPSS
5.3 Medium
CVSS3