CVE-2023-27478
Summary
| CVE | CVE-2023-27478 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-07 18:15:00 UTC |
| Updated | 2023-03-23 16:59:00 UTC |
| Description | libmemcached-awesome is an open source C/C++ client library and tools for the memcached server. `libmemcached` could return data for a previously requested key, if that previous request timed out due to a low `POLL_TIMEOUT`. This issue has been addressed in version 1.1.4. Users are advised to upgrade. There are several ways to workaround or lower the probability of this bug affecting a given deployment. 1: use a reasonably high `POLL_TIMEOUT` setting, like the default. 2: use separate libmemcached connections for unrelated data. 3: do not re-use libmemcached connections in an unknown state. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Disclosure of unrelated data · Advisory · awesomized/libmemcached · GitHub |
MISC |
github.com |
|
| Release v 1.1.4 · awesomized/libmemcached · GitHub |
MISC |
github.com |
|
| revert most of d7a0084bf99d618d1dc26a54fd413db7ae8b8e63 · awesomized/libmemcached@48dcc61 · GitHub |
MISC |
github.com |
|
| get returns random values when lower than default OPT_POLL_TIMEOUT is set · Issue #531 · php-memcached-dev/php-memcached · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 184704 Debian Security Update for libmemcached (CVE-2023-27478)
- 283783 Fedora Security Update for libmemcached (FEDORA-2023-7da1639d3f)
- 283784 Fedora Security Update for libmemcached (FEDORA-2023-c9bbaadcbf)
- 284259 Fedora Security Update for libmemcached (FEDORA-2023-fd848970c4)