CVE-2021-37519
published 2023-02-03CVE-2021-37519: Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to cause a denial of service via crafted authenticattion file.
PriorityP418medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.36%
28.4th percentile
Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to cause a denial of service via crafted authenticattion file.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | memcached | < memcached 1.6.10+dfsg-1 (bookworm) | memcached 1.6.10+dfsg-1 (bookworm) |
| memcached | memcached | — | — |
| memcached | memcached | >= 0 < 1.6.10+dfsg-1 | 1.6.10+dfsg-1 |
| memcached | memcached | >= 0 < 1.6.10+dfsg-1 | 1.6.10+dfsg-1 |
| memcached | memcached | >= 0 < 1.6.10+dfsg-1 | 1.6.10+dfsg-1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_oracle5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Patches (memcached) — CVE-2021-37519
vendor_oracle·2023-04-15·CVSS 5.5
CVE-2021-37519 [MEDIUM] Oracle Oracle Communications Risk Matrix: Patches (memcached) — CVE-2021-37519
Oracle Oracle Communications Risk Matrix: Patches (memcached) vulnerability
CVE: CVE-2021-37519
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2023 (APR 2023)
Red Hat
memcached: Buffer Overflow vulnerability in authfile.c
vendor_redhat·2023-02-03·CVSS 5.5
CVE-2021-37519 [MEDIUM] CWE-119 memcached: Buffer Overflow vulnerability in authfile.c
memcached: Buffer Overflow vulnerability in authfile.c
Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to cause a denial of service via crafted authenticattion file.
A flaw was found in memcached, where it is vulnerable to a denial of service caused by a heap-based buffer overflow in the authfile.c script. By persuading a victim to open a specially-crafted file, an attacker can cause a denial of service.
Package: memcached (Red Hat Enterprise Linux 6) - Not affected
Package: memcached (Red Hat Enterprise Linux 7) - Not affected
Package: memcached (Red Hat Enterprise Linux 8) - Fix deferred
Package: memcached (Red Hat Enterprise Linux 9) - Fix deferred
Package: memcached (Red Hat OpenStack Platform 13 (Queens)) - Out of support scope
Debian
CVE-2021-37519: memcached - Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to ...
vendor_debian·2021·CVSS 5.5
CVE-2021-37519 [MEDIUM] CVE-2021-37519: memcached - Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to ...
Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to cause a denial of service via crafted authenticattion file.
Scope: local
bookworm: resolved (fixed in 1.6.10+dfsg-1)
bullseye: open
forky: resolved (fixed in 1.6.10+dfsg-1)
sid: resolved (fixed in 1.6.10+dfsg-1)
trixie: resolved (fixed in 1.6.10+dfsg-1)
OSV
CVE-2021-37519: Buffer Overflow vulnerability in authfile
osv·2023-02-03·CVSS 5.5
CVE-2021-37519 [MEDIUM] CVE-2021-37519: Buffer Overflow vulnerability in authfile
Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to cause a denial of service via crafted authenticattion file.
GHSA
GHSA-5pff-p34f-mm94: Buffer Overflow vulnerability in authfile
ghsa_unreviewed·2023-02-03
CVE-2021-37519 [MEDIUM] CWE-787 GHSA-5pff-p34f-mm94: Buffer Overflow vulnerability in authfile
Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to cause a denial of service via crafted authenticattion file.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-03
Published