CVE-2011-4971
Multiple integer signedness errors in the (1) process_bin_sasl_auth, (2) process_bin_complete_sasl_auth, (3) process_bin_update, and (4) process_bin_append_prepend functions in Memcached 1.4.5 and earlier allow remote attackers to cause a denial of service (crash) via a large body length value in a packet.
- Affected products
- Memcached
- Memcached
- ≤ 1.4.5, 1.2.7, 1.2.8, 1.4.0, 1.4.1, 1.4.2, 1.4.3, 1.4.4
- Fix
- Available
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 22.3% (98th percentile)
- Weakness
- CWE-189
- NVD status
- Modified
- Published
- 2013-12-12
CVE-2011-4971 at NVD
3 known exploits for CVE-2011-4971
Proof-of-concept code and exploit modules indexed by Sploitus