CVE-2023-46852

Name
CVE-2023-46852
Description
In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there are many spaces after the "get" substring.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/memcached/memcached/commit/76a6c363c18cfe7b6a1524ae64202ac9db330767
MISC https://github.com/memcached/memcached/compare/1.6.21...1.6.22

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:memcached:memcached:*:*:*:*:*:*:*:* memcached >= None < 1.6.22

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
memcached 3.18-main 1.6.21-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
memcached 3.17-main 1.6.17-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
memcached 3.16-main 1.6.15-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
memcached 3.15-main 1.6.12-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable