Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1047299 - (CVE-2013-7239) CVE-2013-7239 memcached: SASL authentication allows wrong credentials to access memcache
CVE-2013-7239 memcached: SASL authentication allows wrong credentials to acce...
Status: CLOSED NOTABUG
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20130419,repor...
: Security
Depends On: 1047300 1047302 1047303
Blocks: 1047305
  Show dependency treegraph
 
Reported: 2013-12-30 05:31 EST by Ratul Gupta
Modified: 2016-03-08 14:14 EST (History)
12 users (show)

See Also:
Fixed In Version: memcached 1.4.17
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2014-01-02 05:53:41 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Ratul Gupta 2013-12-30 05:31:27 EST
Memcached was found to be affected by a SASL authentication bypass glitch.

The issue was that if the attacker makes an invalid request with SASL credentials, it will initially fail. However if he issue a second request with bad SASL credentials, it will authenticate. This way, an attacker can get access to memcache even with wrong SASL credentials.

References:
http://seclists.org/oss-sec/2013/q4/565
https://code.google.com/p/memcached/issues/detail?id=316
https://code.google.com/p/memcached/wiki/ReleaseNotes1417

Commit:
https://github.com/memcached/memcached/commit/87c1cf0f20be20608d3becf854e9cf0910f4ad32
Comment 2 Ratul Gupta 2013-12-30 05:33:19 EST
Created memcached tracking bugs for this issue:

Affects: fedora-all [bug 1047300]
Affects: epel-5 [bug 1047302]
Comment 3 Huzaifa S. Sidhpurwala 2014-01-02 00:16:45 EST
Statement:

Not Vulnerable. This issue does not affect the version of memcached package as shipped with Red Hat Enterprise Linux 5 and 6, since its not compiled with SASL support.
Comment 4 Miroslav Lichvar 2014-01-02 04:58:09 EST
Please note that none of the EPEL, RHEL or Fedora memcached packages are affected by this bug as they are not compiled with SASL support.

Note You need to log in before you can comment on or make changes to this bug.