CVE-2023-46853

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-46853
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-46853.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-46853
Aliases
Downstream
Related
Published
2023-10-27T20:15:09Z
Modified
2025-10-16T10:15:08.179778Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.

References

Affected packages

Git / github.com/memcached/memcached

Affected ranges

Type
GIT
Repo
https://github.com/memcached/memcached
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.3.2
1.3.3
1.4-rc1
1.4.0
1.4.0-rc1
1.4.1
1.4.1-rc1
1.4.10
1.4.11
1.4.11-beta1
1.4.11-rc1
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.18
1.4.19
1.4.2
1.4.2-rc1
1.4.20
1.4.21
1.4.22
1.4.23
1.4.24
1.4.25
1.4.26
1.4.27
1.4.28
1.4.29
1.4.3
1.4.3-rc1
1.4.3-rc2
1.4.30
1.4.31
1.4.32
1.4.33
1.4.34
1.4.35
1.4.36
1.4.37
1.4.38
1.4.39
1.4.4
1.4.5
1.4.6
1.4.6-rc1
1.4.7
1.4.7-rc1
1.4.8
1.4.8-rc1
1.4.9
1.5.0
1.5.1
1.5.10
1.5.11
1.5.12
1.5.13
1.5.14
1.5.15
1.5.16
1.5.17
1.5.18
1.5.19
1.5.2
1.5.20
1.5.21
1.5.22
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.13
1.6.14
1.6.15
1.6.16
1.6.17
1.6.18
1.6.19
1.6.2
1.6.20
1.6.21
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9

Database specific

vanir_signatures

[
    {
        "source": "https://github.com/memcached/memcached/commit/6987918e9a3094ec4fc8976f01f769f624d790fa",
        "id": "CVE-2023-46853-44796e3f",
        "signature_type": "Line",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "file": "proxy_request.c"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "47946276481924199060739875323111071982",
                "50363236966043243406487825298070188660",
                "23466062605571532628824430579373897660",
                "120974074348547489186474730275842439451",
                "317486004054343329936063168509286865411",
                "235505635046735264112593257715574713949",
                "250021219340225387487244066896381193364",
                "54930626506818655552006056162578318635",
                "309807938078896564228508951180636893398",
                "101390803955460101527370920358632305270",
                "245754199818578440380532167988109839948",
                "137318393709646256655536723156665487181",
                "325682194504103582634712444276964465720",
                "14397204291138058740844880962502611265",
                "160832317398044957595462527917122325411",
                "114003440400907505646373005972748960862",
                "89537988329913427290132006849207846058",
                "187461983618611124973223268413284953573",
                "256015744181031489656851227379829368093",
                "222003885644309749962383570708584288037",
                "28893552529520032330584278657942536092",
                "335005052492309134963847603495714926162",
                "199800516433955679268658461589986043182",
                "327334939946895611026008466034247004642"
            ]
        }
    },
    {
        "source": "https://github.com/memcached/memcached/commit/6987918e9a3094ec4fc8976f01f769f624d790fa",
        "id": "CVE-2023-46853-6fbe2cae",
        "signature_type": "Function",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "function": "_process_tokenize",
            "file": "proxy_request.c"
        },
        "digest": {
            "function_hash": "99936839916445165500219790402774692696",
            "length": 748.0
        }
    },
    {
        "source": "https://github.com/memcached/memcached/commit/6987918e9a3094ec4fc8976f01f769f624d790fa",
        "id": "CVE-2023-46853-b1989831",
        "signature_type": "Function",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "function": "_process_request_next_key",
            "file": "proxy_request.c"
        },
        "digest": {
            "function_hash": "270171805113225350048234623312676900648",
            "length": 464.0
        }
    },
    {
        "source": "https://github.com/memcached/memcached/commit/6987918e9a3094ec4fc8976f01f769f624d790fa",
        "id": "CVE-2023-46853-b713c5d6",
        "signature_type": "Line",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "file": "proxy.h"
        },
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "259526308005433963967652210018901918109",
                "111272703029164814931999777419932182974",
                "315298788663692192212937963066493745709",
                "296899313337141795171017791038727304579"
            ]
        }
    },
    {
        "source": "https://github.com/memcached/memcached/commit/6987918e9a3094ec4fc8976f01f769f624d790fa",
        "id": "CVE-2023-46853-bd16d939",
        "signature_type": "Function",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "function": "_process_request_metaflags",
            "file": "proxy_request.c"
        },
        "digest": {
            "function_hash": "117084568997945274655045745534312453940",
            "length": 741.0
        }
    },
    {
        "source": "https://github.com/memcached/memcached/commit/6987918e9a3094ec4fc8976f01f769f624d790fa",
        "id": "CVE-2023-46853-f47f43ab",
        "signature_type": "Function",
        "signature_version": "v1",
        "deprecated": false,
        "target": {
            "function": "process_request",
            "file": "proxy_request.c"
        },
        "digest": {
            "function_hash": "22788301890109828731836979942572917566",
            "length": 3154.0
        }
    }
]