Bugzilla – Bug 857188
VUL-0: CVE-2013-7239: memcached: SASL authentication allows wrong credentials to access memcache
Last modified: 2018-03-26 14:39:56 UTC
OSS:11764 CVE-2013-7239 From upstream release notes for 1.4.17[1] it states "The other notable bug is a SASL authentication bypass glitch. If a client makes an invalid request with SASL credentials, it will initially fail. However if you issue a second request with bad SASL credentials, it will authenticate. This has now been fixed.". The upstream bugreport is at [2], with the corresponding commit fixing this issue at [3]. [1] https://code.google.com/p/memcached/wiki/ReleaseNotes1417 [2] https://code.google.com/p/memcached/issues/detail?id=316 [3] https://github.com/memcached/memcached/commit/87c1cf0f20be20608d3becf854e9cf0910f4ad32 References: https://github.com/memcached/memcached/commit/87c1cf0f20be20608d3becf854e9cf0910f4ad32 http://comments.gmane.org/gmane.comp.security.oss.general/11764
bugbot adjusting priority
SLE has no SASL support enabled. Only openSUSE 12.3 and 13.1 are affected.
This is an autogenerated message for OBS integration: This bug (857188) was mentioned in https://build.opensuse.org/request/show/238633 13.1+12.3 / memcached
openSUSE-SU-2014:0867-1: An update that fixes 5 vulnerabilities is now available. Category: security (moderate) Bug References: 798458,817781,857188,858676,858677 CVE References: CVE-2011-4971,CVE-2013-0179,CVE-2013-7239,CVE-2013-7290,CVE-2013-7291 Sources used: openSUSE 13.1 (src): memcached-1.4.20-6.4.1 openSUSE 12.3 (src): memcached-1.4.20-3.4.1
This only affected openSUSE. update submitted.
update released
openSUSE-SU-2014:0951-1: An update that fixes 5 vulnerabilities is now available. Category: security (moderate) Bug References: 798458,817781,857188,858676,858677 CVE References: CVE-2011-4971,CVE-2013-0179,CVE-2013-7239,CVE-2013-7290,CVE-2013-7291 Sources used: openSUSE 11.4 (src): memcached-1.4.20-7.1
SUSE-SU-2018:0778-1: An update that fixes 9 vulnerabilities is now available. Category: security (important) Bug References: 1007869,1007870,1007871,1056865,798458,817781,857188,858676,858677 CVE References: CVE-2011-4971,CVE-2013-0179,CVE-2013-7239,CVE-2013-7290,CVE-2013-7291,CVE-2016-8704,CVE-2016-8705,CVE-2016-8706,CVE-2017-9951 Sources used: SUSE OpenStack Cloud 7 (src): memcached-1.4.39-3.3.2 SUSE Enterprise Storage 4 (src): memcached-1.4.39-3.3.2
SUSE-SU-2018:0807-1: An update that fixes 9 vulnerabilities is now available. Category: security (important) Bug References: 1007869,1007870,1007871,1056865,798458,817781,857188,858676,858677 CVE References: CVE-2011-4971,CVE-2013-0179,CVE-2013-7239,CVE-2013-7290,CVE-2013-7291,CVE-2016-8704,CVE-2016-8705,CVE-2016-8706,CVE-2017-9951 Sources used: SUSE OpenStack Cloud 6 (src): memcached-1.4.39-3.3.1