An integer overflow in the process_bin_append_prepend function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HMemcached
APPMemcached≤ 1.4.31
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEMemory
CWE
References
Related vulnerabilities
CVE-2023-46853CRITICAL9.8PL ✓same product
Błąd off-by-one w Memcached przy obsłudze proxy (przed 1.6.22)
CVE-2016-8705CRITICAL9.8PL ✓same product
Przepełnienie liczby całkowitej w Memcached umożliwiające zdalne wykonanie kodu
CVE-2026-47783HIGH8.1same product
In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel ...
CVE-2026-47784HIGH8.1same product
In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel ...
CVE-2023-46852HIGH7.5same product
In Memcached before 1.6.22, a buffer overflow exists when processing multiget requests in proxy mode, if there...