CVE-2011-4971: Medium severity memcached vulnerability
Multiple integer signedness errors in the (1) processbinsaslauth, (2) processbincompletesaslauth, (3) processbinupdate, and (4) processbinappendprepend functions in Memcached 1.4.5 and earlier allow remote attackers to cause a denial of service (crash) via a large body length value in a packet.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4971?
CVE-2011-4971 is characterized as a denial of service vulnerability due to integer signedness errors.
How do I fix CVE-2011-4971?
To address CVE-2011-4971, upgrade Memcached to version 1.4.6 or later where the vulnerability has been patched.
Which versions of Memcached are affected by CVE-2011-4971?
CVE-2011-4971 affects Memcached versions 1.4.5 and earlier, along with various earlier versions.
Can CVE-2011-4971 be exploited remotely?
Yes, CVE-2011-4971 can be exploited by remote attackers to crash the Memcached server.
What functions in Memcached are vulnerable in CVE-2011-4971?
The processes 'process_bin_sasl_auth', 'process_bin_complete_sasl_auth', 'process_bin_update', and 'process_bin_append_prepend' are vulnerable in CVE-2011-4971.