PublicDateAtUSN: 2017-07-17 Candidate: CVE-2017-9951 PublicDate: 2017-07-17 13:18:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9951 https://www.twistlock.com/2017/07/13/cve-2017-9951-heap-overflow-memcached-server-1-4-38-twistlock-vulnerability-report/ https://github.com/memcached/memcached/wiki/ReleaseNotes1439 https://groups.google.com/forum/message/raw?msg=memcached/ubGWrkmrr4E/nrm1SeVJAQAJ https://ubuntu.com/security/notices/USN-3588-1 Description: The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation fault) via a request to add/set a key, which makes a comparison between signed and unsigned int and triggers a heap-based buffer over-read. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8705. Ubuntu-Description: Daniel Shapira discovered an integer overflow issue in Memcached. A remote attacker could use this to cause a denial of service (daemon crash). Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=868701 Priority: low Discovered-by: Daniel Shapira Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_memcached: upstream: https://github.com/memcached/memcached/commit/328629445c71e6c17074f6e9e0e3ef585b58f167 upstream_memcached: released (1.4.39) precise/esm_memcached: DNE trusty_memcached: released (1.4.14-0ubuntu9.2) trusty/esm_memcached: DNE (trusty was released [1.4.14-0ubuntu9.2]) vivid/ubuntu-core_memcached: DNE xenial_memcached: released (1.4.25-2ubuntu1.3) esm-infra/xenial_memcached: released (1.4.25-2ubuntu1.3) yakkety_memcached: ignored (reached end-of-life) zesty_memcached: ignored (reached end-of-life) artful_memcached: released (1.4.33-1ubuntu3.2) devel_memcached: not-affected (1.5.4-1ubuntu1)