-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4791-1                [email protected]
https://www.debian.org/lts/security/                          Abhijith PA
September 23, 2026                            https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : memcached
Version        : 1.6.18-1+deb12u1
CVE ID         : CVE-2023-46852 CVE-2023-46853 CVE-2026-47783
                 CVE-2026-47784

Multiple vulnerabilities were found in memcached, high-performance
in-memory object caching system.

CVE-2023-46852

    a buffer overflow exists when processing multiget requests in
    proxy mode, if there are many spaces after the "get" substring

CVE-2023-46853

    an off-by-one error exists when processing proxy requests in proxy
    mode, if \n is used instead of \r\n.

CVE-2026-47783

    username data for SASL password database authentication has a
    timing side channel because a loop exits as soon as a valid
    username is found by sasl_server_userdb_checkpass.

CVE-2026-47784

    password data for SASL password database authentication has a
    timing side channel because memcmp is used by
    sasl_server_userdb_checkpass.

For Debian 12 bookworm, these problems have been fixed in version
1.6.18-1+deb12u1.

We recommend that you upgrade your memcached packages.

For the detailed security status of memcached please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/memcached

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAmqzS8YACgkQhj1N8u2c
KO/4chAAkXBAjGQ2pY5LPQBFPpCAnOsBUZpa7NfZLsRN8awNU+3kwqj/qtRuQWeI
DMHtXqxh4f00Z8B7QcTM+hzNh0VytvEwbMtBQTTwRe0ONrMGbpw7xDwT81Af2s4g
Nw4QHJP4WrzoFVL2k509agM/SLsyTy+W0E+MIkhk2A+5Z9mAVJBu+LPBBZBt8e/d
OLdsW5S1lVKeOkg0cqlKBaIzm9AZKUsvXAeHrehsLiWoLn2YbOJ4vSBgOaMa00+b
YN6CxgdAkF+izlbUUnCyNJXuoxj8jgxsZYAt/NoVZXY7hWB9vQdV0GWyg7joyGW0
YFZxq7tvaZx0MBzk+uqC+Kww61Y45Jt30wan5VWdvW/TvGXH8ZSKnCueXCPABCDt
KqM18rPVAv+enNQ6JzTE7l8BYmUFMB5utV/icnpNgzG8YbHoN/AF6x6Pj5uqIkl6
jEGXzpLbzsNk8uDlWdgEHuGumPcpq+ZRMY4L5uEp6tlylkwajZ2nKvV0rZc9f59q
z9oL/TU2pSOf4tTIhvPFFxqVt1dOxm6i7veSsls4V15TJHBJ9JBsUizWCjnt02zf
izMZWCCuHY2wHHN1heXyPJUskm/wXCfCXTM0eNtUytzIpjAL9w92+bU7VhzF7H6u
P+nQlKt+bIk6g6jYceqgyAYrdpmw9kI5qICmo7TsjvoG3R0w9SM=
=bZMS
-----END PGP SIGNATURE-----

Reply via email to