Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
通过时间差异性导致的信息暴露
Vulnerability Title
Memcached 安全漏洞
Vulnerability Description
Memcached是美国memcached community社区的一套高性能的分布式内存对象缓存系统。 Memcached 1.6.42之前版本存在安全漏洞,该漏洞源于SASL密码数据库认证中用户名数据存在时序侧信道,因为sasl_server_userdb_checkpass在找到有效用户名后立即退出循环。
CVSS Information
N/A
Vulnerability Type
N/A