CVE-2013-0179
published 2014-01-13CVE-2013-0179: The process_bin_delete function in memcached.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remote attackers to…
PriorityP413low1.8CVSS 2.0
AVAACHAuNCNINAP
EPSS
1.50%
71.4th percentile
The process_bin_delete function in memcached.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (segmentation fault) via a request to delete a key, which does not account for the lack of a null terminator in the key and triggers a buffer over-read when printing to stderr.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | memcached | < memcached 1.4.13-0.2 (bookworm) | memcached 1.4.13-0.2 (bookworm) |
| debian | memcached | < memcached 1.4.20-1 (bookworm) | memcached 1.4.20-1 (bookworm) |
| memcached | memcached | <= 1.4.16 | — |
| memcached | memcached | — | — |
| memcached | memcached | — | — |
| memcached | memcached | — | — |
| memcached | memcached | — | — |
| memcached | memcached | — | — |
| memcached | memcached | — | — |
| memcached | memcached | — | — |
| memcached | memcached | — | — |
| memcached | memcached | — | — |
| memcached | memcached | — | — |
| memcached | memcached | — | — |
| memcached | memcached | — | — |
| memcached | memcached | — | — |
| memcached | memcached | — | — |
| memcached | memcached | — | — |
| memcached | memcached | — | — |
| memcached | memcached | — | — |
| memcached | memcached | >= 0 < 1.4.13-0.2 | 1.4.13-0.2 |
| memcached | memcached | >= 0 < 1.4.20-1 | 1.4.20-1 |
| memcached | memcached | >= 0 < 1.4.13-0.2 | 1.4.13-0.2 |
| memcached | memcached | >= 0 < 1.4.20-1 | 1.4.20-1 |
| memcached | memcached | >= 0 < 1.4.13-0.2 | 1.4.13-0.2 |
CVSS provenance
nvdv2.01.8LOWAV:A/AC:H/Au:N/C:N/I:N/A:P
osv1.8LOW
vendor_ubuntu5.0MEDIUM
vendor_debian1.8LOW
vendor_redhat1.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Memcached vulnerabilities
vendor_ubuntu·2014-01-13·CVSS 5.0
CVE-2011-4971 [MEDIUM] Memcached vulnerabilities
Title: Memcached vulnerabilities
Summary: Several security issues were fixed in Memcached.
Stefan Bucur discovered that Memcached incorrectly handled certain large
body lengths. A remote attacker could use this issue to cause Memcached to
crash, resulting in a denial of service. (CVE-2011-4971)
Jeremy Sowden discovered that Memcached incorrectly handled logging certain
details when the -vv option was used. An attacker could use this issue to
cause Memcached to crash, resulting in a denial of service. (CVE-2013-0179)
It was discovered that Memcached incorrectly handled SASL authentication.
A remote attacker could use this issue to bypass SASL authentication
completely. This issue only affected Ubuntu 12.10, Ubuntu 13.04 and Ubuntu
13.10. (CVE-2013-7239)
Instructions: In general, a stan
Red Hat
memcached: remote DoS (crash) via a request that triggers "unbounded key print"
vendor_redhat·2013-01-08·CVSS 1.8
CVE-2013-7291 [LOW] memcached: remote DoS (crash) via a request that triggers "unbounded key print"
memcached: remote DoS (crash) via a request that triggers "unbounded key print"
memcached before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (crash) via a request that triggers an "unbounded key print" during logging, related to an issue that was "quickly grepped out of the source tree," a different vulnerability than CVE-2013-0179 and CVE-2013-7290.
Package: memcached (CloudForms Management Engine 5) - Will not fix
Package: memcached (Red Hat Enterprise Linux 6) - Will not fix
Package: memcached (Red Hat Enterprise Linux 7) - Not affected
Red Hat
memcached: DoS due to buffer overrun when printing out keys to be deleted in verbose mode
vendor_redhat·2013-01-08·CVSS 1.8
CVE-2013-0179 [LOW] memcached: DoS due to buffer overrun when printing out keys to be deleted in verbose mode
memcached: DoS due to buffer overrun when printing out keys to be deleted in verbose mode
The process_bin_delete function in memcached.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (segmentation fault) via a request to delete a key, which does not account for the lack of a null terminator in the key and triggers a buffer over-read when printing to stderr.
Package: memcached (Red Hat Enterprise Linux 6) - Will not fix
Red Hat
memcached: remote DoS (segmentation fault) via a request to delete a key
vendor_redhat·2013-01-08·CVSS 1.8
CVE-2013-7290 [LOW] memcached: remote DoS (segmentation fault) via a request to delete a key
memcached: remote DoS (segmentation fault) via a request to delete a key
The do_item_get function in items.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (segmentation fault) via a request to delete a key, which does not account for the lack of a null terminator in the key and triggers a buffer over-read when printing to stderr, a different vulnerability than CVE-2013-0179.
Package: memcached (CloudForms Management Engine 5) - Will not fix
Package: memcached (Red Hat Enterprise Linux 6) - Will not fix
Package: memcached (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-0179: memcached - The process_bin_delete function in memcached.c in memcached 1.4.4 and other vers...
vendor_debian·2013·CVSS 1.8
CVE-2013-0179 [LOW] CVE-2013-0179: memcached - The process_bin_delete function in memcached.c in memcached 1.4.4 and other vers...
The process_bin_delete function in memcached.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (segmentation fault) via a request to delete a key, which does not account for the lack of a null terminator in the key and triggers a buffer over-read when printing to stderr.
Scope: local
bookworm: resolved (fixed in 1.4.13-0.2)
bullseye: resolved (fixed in 1.4.13-0.2)
forky: resolved (fixed in 1.4.13-0.2)
sid: resolved (fixed in 1.4.13-0.2)
trixie: resolved (fixed in 1.4.13-0.2)
Debian
CVE-2013-7290: memcached - The do_item_get function in items.c in memcached 1.4.4 and other versions before...
vendor_debian·2013·CVSS 1.8
CVE-2013-7290 [LOW] CVE-2013-7290: memcached - The do_item_get function in items.c in memcached 1.4.4 and other versions before...
The do_item_get function in items.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (segmentation fault) via a request to delete a key, which does not account for the lack of a null terminator in the key and triggers a buffer over-read when printing to stderr, a different vulnerability than CVE-2013-0179.
Scope: local
bookworm: resolved (fixed in 1.4.13-0.2)
bullseye: resolved (fixed in 1.4.13-0.2)
forky: resolved (fixed in 1.4.13-0.2)
sid: resolved (fixed in 1.4.13-0.2)
trixie: resolved (fixed in 1.4.13-0.2)
Debian
CVE-2013-7291: memcached - memcached before 1.4.17, when running in verbose mode, allows remote attackers t...
vendor_debian·2013·CVSS 1.8
CVE-2013-7291 [LOW] CVE-2013-7291: memcached - memcached before 1.4.17, when running in verbose mode, allows remote attackers t...
memcached before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (crash) via a request that triggers an "unbounded key print" during logging, related to an issue that was "quickly grepped out of the source tree," a different vulnerability than CVE-2013-0179 and CVE-2013-7290.
Scope: local
bookworm: resolved (fixed in 1.4.20-1)
bullseye: resolved (fixed in 1.4.20-1)
forky: resolved (fixed in 1.4.20-1)
sid: resolved (fixed in 1.4.20-1)
trixie: resolved (fixed in 1.4.20-1)
GHSA
GHSA-73g2-74h6-466w: The do_item_get function in items
ghsa_unreviewed·2022-05-14·CVSS 1.8
CVE-2013-7290 [LOW] CWE-119 GHSA-73g2-74h6-466w: The do_item_get function in items
The do_item_get function in items.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (segmentation fault) via a request to delete a key, which does not account for the lack of a null terminator in the key and triggers a buffer over-read when printing to stderr, a different vulnerability than CVE-2013-0179.
GHSA
GHSA-837m-gcpw-m94w: memcached before 1
ghsa_unreviewed·2022-05-14·CVSS 1.8
CVE-2013-7291 [LOW] CWE-119 GHSA-837m-gcpw-m94w: memcached before 1
memcached before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (crash) via a request that triggers an "unbounded key print" during logging, related to an issue that was "quickly grepped out of the source tree," a different vulnerability than CVE-2013-0179 and CVE-2013-7290.
GHSA
GHSA-w2x5-3r39-4jxq: The process_bin_delete function in memcached
ghsa_unreviewed·2022-05-05
CVE-2013-0179 [LOW] CWE-119 GHSA-w2x5-3r39-4jxq: The process_bin_delete function in memcached
The process_bin_delete function in memcached.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (segmentation fault) via a request to delete a key, which does not account for the lack of a null terminator in the key and triggers a buffer over-read when printing to stderr.
OSV
CVE-2013-0179: The process_bin_delete function in memcached
osv·2014-01-13·CVSS 1.8
CVE-2013-0179 [LOW] CVE-2013-0179: The process_bin_delete function in memcached
The process_bin_delete function in memcached.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (segmentation fault) via a request to delete a key, which does not account for the lack of a null terminator in the key and triggers a buffer over-read when printing to stderr.
OSV
CVE-2013-7291: memcached before 1
osv·2014-01-13·CVSS 1.8
CVE-2013-7291 [LOW] CVE-2013-7291: memcached before 1
memcached before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (crash) via a request that triggers an "unbounded key print" during logging, related to an issue that was "quickly grepped out of the source tree," a different vulnerability than CVE-2013-0179 and CVE-2013-7290.
OSV
CVE-2013-7290: The do_item_get function in items
osv·2014-01-13·CVSS 1.8
CVE-2013-7290 [LOW] CVE-2013-7290: The do_item_get function in items
The do_item_get function in items.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (segmentation fault) via a request to delete a key, which does not account for the lack of a null terminator in the key and triggers a buffer over-read when printing to stderr, a different vulnerability than CVE-2013-0179.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-7290 memcached: remote DoS (segmentation fault) via a request to delete a key
bugzilla·2014-01-14·CVSS 1.8
CVE-2013-7290 [LOW] CVE-2013-7290 memcached: remote DoS (segmentation fault) via a request to delete a key
CVE-2013-7290 memcached: remote DoS (segmentation fault) via a request to delete a key
Common Vulnerabilities and Exposures assigned an identifier CVE-2013-7290 to the following vulnerability:
Name: CVE-2013-7290
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7290
Assigned: 20140110
Reference: https://code.google.com/p/memcached/issues/detail?id=306
Reference: https://code.google.com/p/memcached/wiki/ReleaseNotes1417
The do_item_get function in items.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (segmentation fault) via a request to delete a key, which does not account for the lack of a null terminator in the key and triggers a buffer over-read when printing to stderr, a different vu
Bugzilla
CVE-2013-7291 memcached: remote DoS (crash) via a request that triggers "unbounded key print"
bugzilla·2014-01-14·CVSS 1.8
CVE-2013-7291 [LOW] CVE-2013-7291 memcached: remote DoS (crash) via a request that triggers "unbounded key print"
CVE-2013-7291 memcached: remote DoS (crash) via a request that triggers "unbounded key print"
Common Vulnerabilities and Exposures assigned an identifier CVE-2013-7291 to the following vulnerability:
Name: CVE-2013-7291
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7291
Assigned: 20140110
Reference: https://code.google.com/p/memcached/issues/detail?id=306
Reference: https://code.google.com/p/memcached/wiki/ReleaseNotes1417
memcached before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (crash) via a request that triggers an "unbounded key print" during logging, related to an issue that was "quickly grepped out of the source tree," a different vulnerability than CVE-2013-0179 and CVE-2013-7290.
Discussion:
Created memcached trac
Bugzilla
CVE-2013-0179 memcached: DoS due to buffer overrun when printing out keys to be deleted in verbose mode
bugzilla·2013-01-14·CVSS 1.8
CVE-2013-0179 [LOW] CVE-2013-0179 memcached: DoS due to buffer overrun when printing out keys to be deleted in verbose mode
CVE-2013-0179 memcached: DoS due to buffer overrun when printing out keys to be deleted in verbose mode
Description of problem:
When run with "-vv", on receipt of a binary-protocol deletion request, memcached prints out the key to be deleted in a way that can lead to a buffer overrun and crash.
Version-Release number of selected component (if applicable):
1.4.4, although this currently affects all later versions.
How reproducible:
Run memcached with "-vv", use memrm to send deletion requests and observe output.
Steps to Reproduce:
1. memcached -p 12345 -vv 2>&1 | grep '^Deleting'
2. memrm --servers localhost:12345 --binary ABCDEF xyz
3. Check the output from memcached.
Actual results:
[[email protected]:~] $ memcached -p 2300 -m 64 -c 1024 -r -vv 2>&1 | grep 'Deleting'
De
http://secunia.com/advisories/56183http://www.openwall.com/lists/oss-security/2013/01/14/4http://www.openwall.com/lists/oss-security/2013/01/14/6http://www.securityfocus.com/bid/64978http://www.ubuntu.com/usn/USN-2080-1https://bugzilla.redhat.com/show_bug.cgi?id=895054https://code.google.com/p/memcached/issues/attachmentText?id=306&aid=3060004000&name=0001-Fix-buffer-overrun-when-logging-key-to-delete-in-bin.patch&token=3GEzHThBL5cxmUrsYANkW03RrNY%3A1358179503096https://code.google.com/p/memcached/issues/detail?id=306https://code.google.com/p/memcached/wiki/ReleaseNotes1417http://secunia.com/advisories/56183http://www.openwall.com/lists/oss-security/2013/01/14/4http://www.openwall.com/lists/oss-security/2013/01/14/6http://www.securityfocus.com/bid/64978http://www.ubuntu.com/usn/USN-2080-1https://bugzilla.redhat.com/show_bug.cgi?id=895054https://code.google.com/p/memcached/issues/attachmentText?id=306&aid=3060004000&name=0001-Fix-buffer-overrun-when-logging-key-to-delete-in-bin.patch&token=3GEzHThBL5cxmUrsYANkW03RrNY%3A1358179503096https://code.google.com/p/memcached/issues/detail?id=306https://code.google.com/p/memcached/wiki/ReleaseNotes1417
2014-01-13
Published