|
|
Log in / Subscribe / Register

Scientific Linux alert SLSA-2016:2819-1 (memcached)

From:  Scott Reid <svreid@fnal.gov>
To:  <scientific-linux-errata@listserv.fnal.gov>
Subject:  Security ERRATA Important: memcached on SL7.x x86_64
Date:  Wed, 14 Dec 2016 18:18:23 +0000
Message-ID:  <20161214181823.15409.49239@slpackages.fnal.gov>

Synopsis: Important: memcached security update Advisory ID: SLSA-2016:2819-1 Issue Date: 2016-11-23 CVE Numbers: CVE-2016-8704 CVE-2016-8705 CVE-2016-8706 -- Security Fix(es): * Two integer overflow flaws, leading to heap-based buffer overflows, were found in the memcached binary protocol. An attacker could create a specially crafted message that would cause the memcached server to crash or, potentially, execute arbitrary code. (CVE-2016-8704, CVE-2016-8705) * An integer overflow flaw, leading to a heap-based buffer overflow, was found in memcached's parsing of SASL authentication messages. An attacker could create a specially crafted message that would cause the memcached server to crash or, potentially, execute arbitrary code. (CVE-2016-8706) -- SL7 x86_64 memcached-1.4.15-10.el7_3.1.x86_64.rpm memcached-debuginfo-1.4.15-10.el7_3.1.i686.rpm memcached-debuginfo-1.4.15-10.el7_3.1.x86_64.rpm memcached-devel-1.4.15-10.el7_3.1.i686.rpm memcached-devel-1.4.15-10.el7_3.1.x86_64.rpm - Scientific Linux Development Team


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds