PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection. Note: Third parties have disputed this as not affecting PHP-Memcached directly.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade memcached | Mar 26, 2024 | Apr 5, 2022 |
| Amazon_linux | — | Upgrade php-pecl-memcachedUpgrade php56-pecl-memcachedUpgrade php55-pecl-memcachedUpgrade php71-pecl-memcachedUpgrade php70-pecl-memcachedUpgrade php54-pecl-memcached | Jan 25, 2023 | Apr 5, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub