Debian Security Advisory

DSA-3704-1 memcached -- security update

Date Reported:
03 Nov 2016
Affected Packages:
memcached
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 842811, Bug 842812, Bug 842814.
In Mitre's CVE dictionary: CVE-2016-8704, CVE-2016-8705, CVE-2016-8706.
More information:

Aleksandar Nikolic of Cisco Talos discovered several integer overflow vulnerabilities in memcached, a high-performance memory object caching system. A remote attacker can take advantage of these flaws to cause a denial of service (daemon crash), or potentially to execute arbitrary code.

For the stable distribution (jessie), these problems have been fixed in version 1.4.21-1.1+deb8u1.

We recommend that you upgrade your memcached packages.