Security
Headlines
HeadlinesLatestCVEs

Headline

Ubuntu Security Notice USN-6476-1

Ubuntu Security Notice 6476-1 - It was discovered that Memcached incorrectly handled certain multiget requests in proxy mode. A remote attacker could use this issue to cause Memcached to crash, resulting in a denial of service, or possibly execute arbitrary code. It was discovered that Memcached incorrectly handled certain proxy requests in proxy mode. A remote attacker could use this issue to cause Memcached to crash, resulting in a denial of service, or possibly execute arbitrary code.

Packet Storm
#vulnerability#ubuntu#dos#memcached
==========================================================================Ubuntu Security Notice USN-6476-1November 13, 2023memcached vulnerabilities==========================================================================A security issue affects these releases of Ubuntu and its derivatives:- Ubuntu 23.10- Ubuntu 23.04- Ubuntu 22.04 LTSSummary:Several security issues were fixed in memcached.Software Description:- memcached: High-performance in-memory object caching systemDetails:It was discovered that Memcached incorrectly handled certain multigetrequests in proxy mode. A remote attacker could use this issue to causeMemcached to crash, resulting in a denial of service, or possibly executearbitrary code. (CVE-2023-46852)It was discovered that Memcached incorrectly handled certain proxy requestsin proxy mode. A remote attacker could use this issue to cause Memcached tocrash, resulting in a denial of service, or possibly execute arbitrarycode. (CVE-2023-46853)Update instructions:The problem can be corrected by updating your system to the followingpackage versions:Ubuntu 23.10:   memcached                       1.6.21-1ubuntu0.23.10.1Ubuntu 23.04:   memcached                       1.6.18-1ubuntu0.1Ubuntu 22.04 LTS:   memcached                       1.6.14-1ubuntu0.1In general, a standard system update will make all the necessary changes.References:   https://ubuntu.com/security/notices/USN-6476-1   CVE-2023-46852, CVE-2023-46853Package Information:   https://launchpad.net/ubuntu/+source/memcached/1.6.21-1ubuntu0.23.10.1   https://launchpad.net/ubuntu/+source/memcached/1.6.18-1ubuntu0.1   https://launchpad.net/ubuntu/+source/memcached/1.6.14-1ubuntu0.1

Related news

CVE-2023-46852: proxy: fix buffer overflow with multiget syntax · memcached/memcached@76a6c36

In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many spaces after the "get" substring.

CVE-2023-46853: Comparing 1.6.21...1.6.22 · memcached/memcached

In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.

Packet Storm: Latest News

Falco 0.39.1