Headline
Ubuntu Security Notice USN-6476-1
Ubuntu Security Notice 6476-1 - It was discovered that Memcached incorrectly handled certain multiget requests in proxy mode. A remote attacker could use this issue to cause Memcached to crash, resulting in a denial of service, or possibly execute arbitrary code. It was discovered that Memcached incorrectly handled certain proxy requests in proxy mode. A remote attacker could use this issue to cause Memcached to crash, resulting in a denial of service, or possibly execute arbitrary code.
==========================================================================Ubuntu Security Notice USN-6476-1November 13, 2023memcached vulnerabilities==========================================================================A security issue affects these releases of Ubuntu and its derivatives:- Ubuntu 23.10- Ubuntu 23.04- Ubuntu 22.04 LTSSummary:Several security issues were fixed in memcached.Software Description:- memcached: High-performance in-memory object caching systemDetails:It was discovered that Memcached incorrectly handled certain multigetrequests in proxy mode. A remote attacker could use this issue to causeMemcached to crash, resulting in a denial of service, or possibly executearbitrary code. (CVE-2023-46852)It was discovered that Memcached incorrectly handled certain proxy requestsin proxy mode. A remote attacker could use this issue to cause Memcached tocrash, resulting in a denial of service, or possibly execute arbitrarycode. (CVE-2023-46853)Update instructions:The problem can be corrected by updating your system to the followingpackage versions:Ubuntu 23.10: memcached 1.6.21-1ubuntu0.23.10.1Ubuntu 23.04: memcached 1.6.18-1ubuntu0.1Ubuntu 22.04 LTS: memcached 1.6.14-1ubuntu0.1In general, a standard system update will make all the necessary changes.References: https://ubuntu.com/security/notices/USN-6476-1 CVE-2023-46852, CVE-2023-46853Package Information: https://launchpad.net/ubuntu/+source/memcached/1.6.21-1ubuntu0.23.10.1 https://launchpad.net/ubuntu/+source/memcached/1.6.18-1ubuntu0.1 https://launchpad.net/ubuntu/+source/memcached/1.6.14-1ubuntu0.1
Related news
In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many spaces after the "get" substring.
In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.