CVE-2023-46853: Critical severity memcached vulnerability
Published Oct 27, 2023
·Updated
In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.
Affected Software
1 affected component
Memcached Memcached<1.6.22
Remediation
Event History
Oct 27, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-46853.
2
What is the severity rating of CVE-2023-46853?
CVE-2023-46853 has a severity rating of critical.
3
What is the affected software version range for CVE-2023-46853?
CVE-2023-46853 affects Memcached versions up to but excluding 1.6.22.
4
What is the CWE ID associated with CVE-2023-46853?
The CWE ID associated with CVE-2023-46853 is CWE-193.
5
How can I fix the vulnerability described in CVE-2023-46853?
To fix this vulnerability, update Memcached to version 1.6.22 or later.