Multiple integer signedness errors in the (1) process_bin_sasl_auth, (2) process_bin_complete_sasl_auth, (3) process_bin_update, and (4) process_bin_append_prepend functions in Memcached 1.4.5 and earlier allow remote attackers to cause a denial of service (crash) via a large body length value in a packet.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade memcached | Aug 30, 2017 | Dec 12, 2013 |
| Debian | — | Upgrade memcached | Jul 30, 2024 | Dec 12, 2013 |
| Gentoo Linux | — | Upgrade net-misc/memcached. | Oct 30, 2017 | Dec 12, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 15, 2011 |
| Suse | — | Upgrade memcached | Jul 4, 2014 | Dec 12, 2013 |
| Ubuntu | — | Upgrade memcached | Nov 8, 2024 | Dec 12, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub