CVE-2016-8706: Integer Overflow
Published Jan 6, 2017
·Updated
An integer overflow in processbinsaslauth function in Memcached, which is responsible for authentication commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.
Affected Software
1 affected component
Memcached Memcached<=1.4.31
Event History
Jan 6, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-8706?
CVE-2016-8706 is classified as a high severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2016-8706?
To fix CVE-2016-8706, upgrade Memcached to version 1.4.32 or later.
3
What type of vulnerability is CVE-2016-8706?
CVE-2016-8706 is an integer overflow vulnerability that can lead to heap overflow.
4
Which versions of Memcached are affected by CVE-2016-8706?
Memcached versions up to and including 1.4.31 are affected by CVE-2016-8706.
5
What could an exploit of CVE-2016-8706 allow an attacker to do?
Exploiting CVE-2016-8706 could allow an attacker to execute arbitrary code remotely on the server.