CVE-2019-11596: Null Pointer Dereference
In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru tempttl" commands. This causes a denial of service when parsing crafted lru command messages in processlrucommand in memcached.c.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this memcached vulnerability?
The vulnerability ID for this memcached vulnerability is CVE-2019-11596.
What is the severity of CVE-2019-11596?
The severity of CVE-2019-11596 is high (7.5).
What software versions are affected by CVE-2019-11596?
Versions of memcached before 1.5.14 are affected by CVE-2019-11596.
How can I fix CVE-2019-11596?
You can fix CVE-2019-11596 by upgrading memcached to version 1.5.14 or later.
Where can I find more information about CVE-2019-11596?
You can find more information about CVE-2019-11596 at the following references: [1](http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00060.html), [2](https://github.com/memcached/memcached/commit/d35334f368817a77a6bd1f33c6a5676b2c402c02), [3](https://github.com/memcached/memcached/compare/ee1cfe3...50bdc9f).