CVE-2016-8704

NameCVE-2016-8704
DescriptionAn integer overflow in the process_bin_append_prepend function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-701-1, DSA-3704-1
NVD severityhigh (attack range: remote)
Debian Bugs842811

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
memcached (PTS)wheezy1.4.13-0.2+deb7u1vulnerable
wheezy (security)1.4.13-0.2+deb7u3fixed
jessie (security), jessie1.4.21-1.1+deb8u1fixed
stretch1.4.33-1fixed
buster, sid1.5.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
memcachedsource(unstable)1.4.33-1high842811
memcachedsourcejessie1.4.21-1.1+deb8u1highDSA-3704-1
memcachedsourcewheezy1.4.13-0.2+deb7u2highDLA-701-1

Notes

http://www.talosintelligence.com/reports/TALOS-2016-0219/
upstream fix https://github.com/memcached/memcached/commit/bd578fc34b96abe0f8d99c1409814a09f51ee71c

Search for package or bug name: Reporting problems