Improper authentication in memcached - CVE-2013-7239

 

Improper authentication in memcached - CVE-2013-7239

Published: March 29, 2018


Vulnerability identifier: #VU11320
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-7239
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication on the target system.

The weakness exists due to allowing wrong credentials access. A remote attacker can send an invalid request with SASL credentials, then send another request with incorrect SASL credentials and bypass authentication.

Affected software

memcached
Debian Linux
Ubuntu
memcached (Alpine package)

How to mitigate CVE-2013-7239

Update to version 1.4.17.

memcached (Alpine package) - update to 1.4.17-r0

External References

Related Security Bulletins