Security update for memcached
This update for memcached fixes the following issues: Security issues fixed: - CVE-2011-4971: remote DoS (bsc#817781). - CVE-2013-0179: DoS when printing out keys to be deleted in verbose mode (bsc#798458). - CVE-2013-7239: SASL authentication allows wrong credentials to access memcache (bsc#857188). - CVE-2013-7290: remote DoS (segmentation fault) via a request to delete a key (bsc#858677). - CVE-2013-7291: remote DoS (crash) via a request that triggers 'unbounded key print' (bsc#858676). - CVE-2016-8704: Server append/prepend remote code execution (bsc#1007871). - CVE-2016-8705: Server update remote code execution (bsc#1007870). - CVE-2016-8706: Server ASL authentication remote code execution (bsc#1007869). - CVE-2017-9951: Heap-based buffer over-read in try_read_command function (incomplete fix for CVE-2016-8705) (bsc#1056865).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for memcached fixes the following issues: Security issues fixed: - CVE-2011-4971: remote DoS (bsc#817781). - CVE-2013-0179: DoS when printing out keys to be deleted in verbose mode (bsc#798458). - CVE-2013-7239: SASL authentication allows wrong credentials to access memcache (bsc#857188). - CVE-2013-7290: remote DoS (segmentation fault) via a request to delete a key (bsc#858677). - CVE-2013-7291: remote DoS (crash) via a request that triggers 'unbounded key print' (bsc#858676). - CVE-2016-8704: Server append/prepend remote code execution (bsc#1007871). - CVE-2016-8705: Server update remote code execution (bsc#1007870). - CVE-2016-8706: Server ASL authentication remote code execution (bsc#1007869). - CVE-2017-9951: Heap-based buffer over-read in try_read_command function (incomplete fix for CVE-2016-8705) (bsc#1056865).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1007869
- https://bugzilla.suse.com/1007870
- https://bugzilla.suse.com/1007871
- https://bugzilla.suse.com/1056865
- https://bugzilla.suse.com/798458
- https://bugzilla.suse.com/817781
- https://bugzilla.suse.com/857188
- https://bugzilla.suse.com/858676
- https://bugzilla.suse.com/858677
- https://www.suse.com/security/cve/CVE-2011-4971
- https://www.suse.com/security/cve/CVE-2013-0179
- https://www.suse.com/security/cve/CVE-2013-7239
- https://www.suse.com/security/cve/CVE-2013-7290
- https://www.suse.com/security/cve/CVE-2013-7291
- https://www.suse.com/security/cve/CVE-2016-8704
- https://www.suse.com/security/cve/CVE-2016-8705
- https://www.suse.com/security/cve/CVE-2016-8706
- https://www.suse.com/security/cve/CVE-2017-9951
- https://www.suse.com/support/update/announcement/2018/suse-su-20180778-1/