Back

CRITICAL

memcached: Server append/prepend remote code execution

Published Jan 6, 2017

Description

An integer overflow in the process_bin_append_prepend function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.

Affected products

Remediation

Red Hat statement

The versions of memcached as shipped with Red Hat OpenStack Platform 7, 8 and 9 are affected by this issue however will not be updated. The latest version of memcached from Red Hat Enterprise Linux 7 can safely be allowed to supersede the earlier versions provided in the Red Hat OpenStack Platform channels.

Red Hat mitigation

This flaw is in the memcached binary protocol. If you client programs only use the ASCII protocol when communicating with memcached, you can disable the binary protocol and protect against this flaw by adding "-B ascii" to OPTIONS in /etc/sysconfig/memcached.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner talos
Published Jan 6, 2017
Updated Aug 6, 2024
Reserved Oct 17, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Oct 31, 2016