Heap-based buffer overflow in memcached - CVE-2016-8706

 

Heap-based buffer overflow in memcached - CVE-2016-8706

Published: October 1, 2016 / Updated: April 2, 2018


Vulnerability identifier: #VU4140
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-8706
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists in the process_bin_sasl_auth() function due to integer overflow. A remote attacker can send specially crafted Memcached binary protocol commands, trigger heap-based buffer overflow and execute arbitrary code.

Successful exploitation of the vulnerability may result in system compromise.

Affected software

memcached
Arch Linux
Debian Linux
Gentoo Linux
Amazon Linux AMI
Ubuntu
Fedora
memcached (Alpine package)
memcached

How to mitigate CVE-2016-8706

Install update from vendor's website.

memcached (Alpine package) - update to 1.4.33-r0
memcached - addressed in versions 1.4.17-5.fc23, 1.4.25-2.fc24, 1.4.33-1.fc25

External References

Related Security Bulletins