[Secure-testing-team] Bug#842812: memcached: CVE-2016-8705

Salvatore Bonaccorso carnil at debian.org
Tue Nov 1 13:05:19 UTC 2016


Source: memcached
Version: 1.4.31-1
Severity: important
Tags: security upstream

Hi,

the following vulnerability was published for memcached.

CVE-2016-8705[0]:
Memcached Server Update Remote Code Execution Vulnerability

It is reproducible with the (fixed) reproducer on the TALOS site, when
running under valgrind easily.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2016-8705
[1] http://www.talosintelligence.com/reports/TALOS-2016-0220/

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



More information about the Secure-testing-team mailing list