CVE-2022-26635

Name
CVE-2022-26635
Description
PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://xhzeem.me/posts/Php5-memcached-Injection-Bypass/read/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:php:memcached:*:*:*:*:*:*:*:* memcached >= None <= 2.2.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
memcached 3.15-main 1.6.12-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
memcached 3.14-main 1.6.9-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
memcached 3.13-main 1.6.9-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
memcached 3.12-main 1.6.6-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
memcached 3.16-main 1.6.15-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
memcached 3.17-main 1.6.17-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
memcached edge-main 1.6.19-r0 Natanael Copa <ncopa@alpinelinux.org> fixed