Name | CVE-2013-7291 |
Description | memcached before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (crash) via a request that triggers an "unbounded key print" during logging, related to an issue that was "quickly grepped out of the source tree," a different vulnerability than CVE-2013-0179 and CVE-2013-7290. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-701-1 |
Debian Bugs | 735314 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
memcached (PTS) | bullseye | 1.6.9+dfsg-1 | fixed |
bookworm | 1.6.18-1 | fixed | |
trixie | 1.6.32-1 | fixed | |
sid | 1.6.32-2 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
memcached | source | wheezy | 1.4.13-0.2+deb7u2 | DLA-701-1 | ||
memcached | source | (unstable) | 1.4.20-1 | low | 735314 |
[squeeze] - memcached <no-dsa> (Minor issue)
https://github.com/memcached/memcached/commit/fbe823d9a61b5149cd6e3b5e17bd28dd3b8dd760