First published: Tue Nov 01 2016(Updated: )
An integer overflow in the process_bin_append_prepend function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/memcached | <1.4.33 | 1.4.33 |
Php Memcached | <=1.4.31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8704 has a critical severity rating as it can lead to remote code execution due to a potential heap overflow.
To fix CVE-2016-8704, upgrade Memcached to version 1.4.33 or later.
CVE-2016-8704 affects Memcached versions up to and including 1.4.31.
Yes, CVE-2016-8704 can be exploited remotely, allowing attackers to execute arbitrary code.
There are no officially documented workarounds for CVE-2016-8704; upgrading to the patched version is recommended.