Debian Security Advisory

DLA-1913-1 memcached -- LTS security update

Date Reported:
07 Sep 2019
Affected Packages:
memcached
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2019-15026.
More information:

It was discovered that there was stack-based buffer over-read in memcached, the in-memory caching server.

  • CVE-2019-15026

    memcached 1.5.16, when UNIX sockets are used, has a stack-based buffer over-read in conn_to_str in memcached.c.

For Debian 8 Jessie, these problems have been fixed in version 1.4.21-1.1+deb8u3.

We recommend that you upgrade your memcached packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS