Home
HIGH: 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
Any version before 1.6.42
affected
Description
In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.
Problem types
CWE-208 Observable Timing Discrepancy
Product status
Any version before 1.6.42
References
github.com/...ommit/d13f282b4bce33a9c33b8a1bbf07f12114160fed
github.com/memcached/memcached/compare/1.6.41...1.6.42
github.com/memcached/memcached/wiki/ReleaseNotes1642