Groups
Groups
Sign in
Groups
Groups
Security News
Conversations
About
Send feedback
Help
RCE in Memcached
240 views
Skip to first unread message
abduladil02
unread,
Nov 2, 2016, 11:02:01 PM
11/2/16
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Security News
Three new vulnerabilities have been found in popular cache system for web apps
CVSS Score:
9.8 [CRITICAL]
CVE-2016-8704:
Memcached Server Append/Prepend Remote Code Execution Vulnerability CVSS:
9.8
CVE-2016-8705:
Memcached Server Update Remote Code Execution Vulnerability CVSS:
8.1
CVE-2016-8706:
Memcached Server SASL Authentication Remote Code Execution Vulnerability CVSS:
9.8
Impact:
If exploited, the vulnerabilities could allow attackers to send repeat specifically-crafted Memcached commands to the targeted servers.
Affects:
The integer overflow flaws in Memcached affect Memcached version 1.4.31 and earlier.
Fix:
Memcached released patch on 31st OCT 2016
Link:
https://github.com/memcached/memcached/wiki/ReleaseNotes1433
http://blog.talosintel.com/2016/10/memcached-vulnerabilities.html
Jassi
unread,
Nov 7, 2016, 5:35:13 AM
11/7/16
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Security News
This is interesting. Thanks for sharing Abdul
Reply all
Reply to author
Forward
0 new messages