Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 916510 (CVE-2023-46852, CVE-2023-46853) - <net-misc/memcached-1.6.22: multiple vulnerabilities
Summary: <net-misc/memcached-1.6.22: multiple vulnerabilities
Status: CONFIRMED
Alias: CVE-2023-46852, CVE-2023-46853
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [glsa? cleanup]
Keywords:
Depends on:
Blocks:
 
Reported: 2023-10-29 21:38 UTC by John Helmert III
Modified: 2023-10-29 21:38 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-10-29 21:38:07 UTC
CVE-2023-46852:

In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many spaces after the "get" substring.

Patch: https://github.com/memcached/memcached/commit/76a6c363c18cfe7b6a1524ae64202ac9db330767

CVE-2023-46853:

In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.

Patch: https://github.com/memcached/memcached/commit/6987918e9a3094ec4fc8976f01f769f624d790fa