Back to Database
Status published
High
CVE-2019-15026
memcached 1.5.16, when UNIX sockets are used, has a stack-based...
Vulnerability Description
memcached 1.5.16, when UNIX sockets are used, has a stack-based buffer over-read in conn_to_str in memcached.c.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-15026
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/memcached/memcached/wiki/ReleaseNotes1517
- https://github.com/memcached/memcached/commit/554b56687a19300a75ec24184746b5512580c819
- https://lists.debian.org/debian-lts-announce/2019/09/msg00006.html
- https://usn.ubuntu.com/4125-1/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EOD422IS2OPXRDID5EKFZHFUHK2BLQGJ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QDBV5OGV3FJDAH4NO4JSXNRWHDGGKWYB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FYGUBOEM5HX4GRMWVEKOJUFICF77ME47/
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00060.html
More from memcached
View All →CVE-2022-48571
memcached 1.6.7 allows a Denial of Service via multi-packet uploads...
High
7.5
CVE-2021-37519
Buffer Overflow vulnerability in authfile.c memcached 1.6.9 allows attackers to...
Unknown
0
CVE-2020-22570
Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a...
High
7.5
CVE-2020-10931
Memcached 1.6.x before 1.6.2 allows remote attackers to cause a...
High
7.5
CVE-2019-11596
In memcached before 1.5.14, a NULL pointer dereference was found...
High
7.5
Affected Vendor
memcached
View all reports →Affected Software
memcached
Vulnerable Versions:
1.5.16
Timeline
Official Publish:
August 30th, 2019
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.