Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
通过时间差异性导致的信息暴露
Vulnerability Title
Memcached 安全漏洞
Vulnerability Description
Memcached是美国memcached community社区的一套高性能的分布式内存对象缓存系统。 Memcached 1.6.42之前版本存在安全漏洞,该漏洞源于SASL密码数据库认证中密码数据存在时序侧信道,因为sasl_server_userdb_checkpass使用了memcmp进行比较。
CVSS Information
N/A
Vulnerability Type
N/A