Bug 857188 (CVE-2013-7239) - VUL-0: CVE-2013-7239: memcached: SASL authentication allows wrong credentials to access memcache
Summary: VUL-0: CVE-2013-7239: memcached: SASL authentication allows wrong credentials...
Status: VERIFIED FIXED
Alias: CVE-2013-7239
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 13.1
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-01-02 12:42 UTC by Alexander Bergmann
Modified: 2018-03-26 14:39 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2014-01-02 12:42:40 UTC
OSS:11764
CVE-2013-7239

From upstream release notes for 1.4.17[1] it states "The other notable
bug is a SASL authentication bypass glitch. If a client makes an
invalid request with SASL credentials, it will initially fail. However
if you issue a second request with bad SASL credentials, it will
authenticate. This has now been fixed.".

The upstream bugreport is at [2], with the corresponding commit fixing
this issue at [3].

 [1] https://code.google.com/p/memcached/wiki/ReleaseNotes1417
 [2] https://code.google.com/p/memcached/issues/detail?id=316
 [3] https://github.com/memcached/memcached/commit/87c1cf0f20be20608d3becf854e9cf0910f4ad32

References:
https://github.com/memcached/memcached/commit/87c1cf0f20be20608d3becf854e9cf0910f4ad32
http://comments.gmane.org/gmane.comp.security.oss.general/11764
Comment 1 Swamp Workflow Management 2014-01-02 23:00:21 UTC
bugbot adjusting priority
Comment 2 Alexander Bergmann 2014-01-10 16:07:34 UTC
SLE has no SASL support enabled. Only openSUSE 12.3 and 13.1 are affected.
Comment 3 Bernhard Wiedemann 2014-06-25 14:00:32 UTC
This is an autogenerated message for OBS integration:
This bug (857188) was mentioned in
https://build.opensuse.org/request/show/238633 13.1+12.3 / memcached
Comment 4 Swamp Workflow Management 2014-07-03 14:04:58 UTC
openSUSE-SU-2014:0867-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 798458,817781,857188,858676,858677
CVE References: CVE-2011-4971,CVE-2013-0179,CVE-2013-7239,CVE-2013-7290,CVE-2013-7291
Sources used:
openSUSE 13.1 (src):    memcached-1.4.20-6.4.1
openSUSE 12.3 (src):    memcached-1.4.20-3.4.1
Comment 5 Marcus Rückert 2014-07-07 15:15:36 UTC
This only affected openSUSE. update submitted.
Comment 6 Johannes Segitz 2014-07-07 16:03:14 UTC
update released
Comment 7 Swamp Workflow Management 2014-07-30 18:48:27 UTC
openSUSE-SU-2014:0951-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 798458,817781,857188,858676,858677
CVE References: CVE-2011-4971,CVE-2013-0179,CVE-2013-7239,CVE-2013-7290,CVE-2013-7291
Sources used:
openSUSE 11.4 (src):    memcached-1.4.20-7.1
Comment 8 Swamp Workflow Management 2018-03-22 16:29:06 UTC
SUSE-SU-2018:0778-1: An update that fixes 9 vulnerabilities is now available.

Category: security (important)
Bug References: 1007869,1007870,1007871,1056865,798458,817781,857188,858676,858677
CVE References: CVE-2011-4971,CVE-2013-0179,CVE-2013-7239,CVE-2013-7290,CVE-2013-7291,CVE-2016-8704,CVE-2016-8705,CVE-2016-8706,CVE-2017-9951
Sources used:
SUSE OpenStack Cloud 7 (src):    memcached-1.4.39-3.3.2
SUSE Enterprise Storage 4 (src):    memcached-1.4.39-3.3.2
Comment 9 Swamp Workflow Management 2018-03-26 13:10:52 UTC
SUSE-SU-2018:0807-1: An update that fixes 9 vulnerabilities is now available.

Category: security (important)
Bug References: 1007869,1007870,1007871,1056865,798458,817781,857188,858676,858677
CVE References: CVE-2011-4971,CVE-2013-0179,CVE-2013-7239,CVE-2013-7290,CVE-2013-7291,CVE-2016-8704,CVE-2016-8705,CVE-2016-8706,CVE-2017-9951
Sources used:
SUSE OpenStack Cloud 6 (src):    memcached-1.4.39-3.3.1