CVE-2016-8705: Integer Overflow
Multiple integer overflows in processbinupdate function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.
Other sources
Multiple integer overflows in processbinupdate function which is responsible for processing multiple commands of Memcached binary protocol can be abused to cause heap overflow and lead to remote code execution.
External References:
http://www.talosintelligence.com/reports/TALOS-2016-0220/
Upstream patch:
https://github.com/memcached/memcached/commit/bd578fc34b96abe0f8d99c1409814a09f51ee71c
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8705?
CVE-2016-8705 has a high severity due to the potential for remote code execution resulting from integer overflows.
How do I fix CVE-2016-8705?
To fix CVE-2016-8705, upgrade to Memcached version 1.4.33 or later.
What software versions are affected by CVE-2016-8705?
Versions of Memcached up to and including 1.4.31 are affected by CVE-2016-8705.
Can CVE-2016-8705 lead to security vulnerabilities?
Yes, CVE-2016-8705 can lead to significant security vulnerabilities, including remote code execution.
What is the impact of CVE-2016-8705 on Memcached?
The impact of CVE-2016-8705 is a potential heap overflow that can compromise server integrity and allow attackers to execute arbitrary code.