Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2022-26635 #519

Closed
eslerm opened this issue Aug 30, 2022 · 4 comments
Closed

CVE-2022-26635 #519

eslerm opened this issue Aug 30, 2022 · 4 comments

Comments

@eslerm
Copy link

eslerm commented Aug 30, 2022

Hello, I have a few questions about this CVE.

CVE-2022-26635: PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection.

Will CVE-2022-26635 123 be patched for php-memcached version 2.2.x?

Does this vulnerability impact any 3.x versions?

Might this impact libmemcached?

Thank you 🙏

Footnotes

  1. https://nvd.nist.gov/vuln/detail/CVE-2022-26635

  2. https://xhzeem.me/posts/Php5-memcached-Injection-Bypass/read/

  3. https://github.com/advisories/GHSA-hph6-79wj-qqmw

@m6w6
Copy link
Contributor

m6w6 commented Sep 27, 2022

This should not be a CVE against php-memcached, but for whatever software the issue was actually found in.
php-memcached and libmemcached provide a VERIFY_KEY flag if they're too lazy to filter untrusted user input.

@eslerm
Copy link
Author

eslerm commented Sep 27, 2022

Thank you for the clarification @m6w6 🙏

I have sent MITRE a request to remove php-memcached from this CVE and referenced your response.

@eslerm eslerm closed this as completed Sep 27, 2022
@carnil
Copy link

carnil commented Mar 1, 2023

Thank you for the clarification @m6w6 pray

I have sent MITRE a request to remove php-memcached from this CVE and referenced your response.

was there any response?

@eslerm
Copy link
Author

eslerm commented Mar 1, 2023

I have not heard back. The owning CNA is MITRE.

I'll ask for an update and CC you.

kraj pushed a commit to YoeDistro/meta-openembedded that referenced this issue Dec 19, 2024
Per [1] this is a problem of applications using memcached inproperly.

This should not be a CVE against php-memcached, but for whatever
software the issue was actually found in. php-memcached and
libmemcached provide a VERIFY_KEY flag if they're too lazy to
filter untrusted user input.

[1] php-memcached-dev/php-memcached#519

Signed-off-by: Peter Marko <[email protected]>
Signed-off-by: Khem Raj <[email protected]>
daregit pushed a commit to daregit/yocto-combined that referenced this issue Dec 21, 2024
Per [1] this is a problem of applications using memcached inproperly.

This should not be a CVE against php-memcached, but for whatever
software the issue was actually found in. php-memcached and
libmemcached provide a VERIFY_KEY flag if they're too lazy to
filter untrusted user input.

[1] php-memcached-dev/php-memcached#519

Signed-off-by: Peter Marko <peter.markosiemens.com>
Signed-off-by: Khem Raj <raj.khemgmail.com>
daregit pushed a commit to daregit/yocto-combined that referenced this issue Dec 22, 2024
Per [1] this is a problem of applications using memcached inproperly.

This should not be a CVE against php-memcached, but for whatever
software the issue was actually found in. php-memcached and
libmemcached provide a VERIFY_KEY flag if they're too lazy to
filter untrusted user input.

[1] php-memcached-dev/php-memcached#519

Signed-off-by: Peter Marko <peter.markosiemens.com>
Signed-off-by: Khem Raj <raj.khemgmail.com>
github-actions bot pushed a commit to Boeing/meta-openembedded-contrib that referenced this issue Jan 5, 2025
Per [1] this is a problem of applications using memcached inproperly.

This should not be a CVE against php-memcached, but for whatever
software the issue was actually found in. php-memcached and
libmemcached provide a VERIFY_KEY flag if they're too lazy to
filter untrusted user input.

[1] php-memcached-dev/php-memcached#519

Signed-off-by: Peter Marko <[email protected]>
Signed-off-by: Khem Raj <[email protected]>
(cherry picked from commit 889ccce)
Signed-off-by: Armin Kuster <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants