Buffer access with incorrect length value in memcached - CVE-2011-4971
Published: March 29, 2018 / Updated: September 14, 2018
Vulnerability identifier: #VU11318
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-4971
CWE-ID: CWE-805
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists in the (1) process_bin_sasl_auth, (2) process_bin_complete_sasl_auth, (3) process_bin_update, and (4) process_bin_append_prepend functions due to a large body length value in a packet. A remote attacker can trigger memory corruption and cause the service to crash.
The weakness exists in the (1) process_bin_sasl_auth, (2) process_bin_complete_sasl_auth, (3) process_bin_update, and (4) process_bin_append_prepend functions due to a large body length value in a packet. A remote attacker can trigger memory corruption and cause the service to crash.
Affected software
memcached
Debian Linux
Ubuntu
memcached (Alpine package)
Debian Linux
Ubuntu
memcached (Alpine package)
How to mitigate CVE-2011-4971
Install update from vendor's website.
memcached (Alpine package) - addressed in versions 1.4.15-r0, 1.4.15-r1, 1.4.15-r2, 1.4.20-r0, 1.4.22-r0, 1.4.25-r0
- update to 2.11-8ubuntu4
- update to 2.11-8ubuntu4
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Ubuntu update for Memcached
- Debian update for memcached
- SUSE Linux update for memcached
- SUSE Linux update for memcached
- Buffer access with incorrect length value in Aconf
- Buffer access with incorrect length value in Aconf
- Buffer access with incorrect length value in memcached (Alpine package)
- Buffer access with incorrect length value in Aconf