[Secure-testing-team] Bug#735314: memcached: CVE-2013-7291

Salvatore Bonaccorso carnil at debian.org
Tue Jan 14 15:54:59 UTC 2014


Package: memcached
Version: 1.4.5-1
Severity: important
Tags: security upstream patch fixed-upstream

Hi,

the following vulnerability was published for memcached.

CVE-2013-7291[0]:
denial of service issue via unbounded key print

In [1] there are mentioned two additional fixes, where CVE-2013-7290
should be already addressed (touches items.c) in 1.4.13-0.2 and
1.4.5-1+deb6u1.

CVE-2013-7291 seems for the additonal commit touching memcached.c in
[2].

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7291
    http://security-tracker.debian.org/tracker/CVE-2013-7291
[1] https://code.google.com/p/memcached/issues/detail?id=306#c7
[2] https://github.com/memcached/memcached/commit/fbe823d9a61b5149cd6e3b5e17bd28dd3b8dd760

Regards,
Salvatore



More information about the Secure-testing-team mailing list