~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2016-8706

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDateAtUSN: 2016-11-02
2
 
Candidate: CVE-2016-8706
3
 
PublicDate: 2017-01-06
4
 
References: 
5
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8706
6
 
 http://blog.talosintel.com/2016/10/memcached-vulnerabilities.html
7
 
 http://www.talosintelligence.com/reports/TALOS-2016-0221/
8
 
 https://github.com/memcached/memcached/wiki/ReleaseNotes1433
9
 
 https://usn.ubuntu.com/usn/usn-3120-1
10
 
Description:
11
 
 An integer overflow in process_bin_sasl_auth function in Memcached, which
12
 
 is responsible for authentication commands of Memcached binary protocol,
13
 
 can be abused to cause heap overflow and lead to remote code execution.
14
 
Ubuntu-Description: 
15
 
Notes: 
16
 
Bugs: 
17
 
Priority: high
18
 
Discovered-by: Aleksandar Nikolic
19
 
Assigned-to: mdeslaur
20
 
 
21
 
Patches_memcached:
22
 
 upstream: https://github.com/memcached/memcached/commit/bd578fc34b96abe0f8d99c1409814a09f51ee71c
23
 
upstream_memcached: released (1.4.33)
24
 
precise_memcached: released (1.4.13-0ubuntu2.2)
25
 
trusty_memcached: released (1.4.14-0ubuntu9.1)
26
 
vivid/stable-phone-overlay_memcached: DNE
27
 
vivid/ubuntu-core_memcached: DNE
28
 
xenial_memcached: released (1.4.25-2ubuntu1.2)
29
 
yakkety_memcached: released (1.4.25-2ubuntu2.1)
30
 
devel_memcached: released (1.4.25-2ubuntu3)