First published: Fri Jan 06 2017(Updated: )
An integer overflow in process_bin_sasl_auth function in Memcached, which is responsible for authentication commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Php Memcached | <=1.4.31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8706 is classified as a high severity vulnerability due to the potential for remote code execution.
To fix CVE-2016-8706, upgrade Memcached to version 1.4.32 or later.
CVE-2016-8706 is an integer overflow vulnerability that can lead to heap overflow.
Memcached versions up to and including 1.4.31 are affected by CVE-2016-8706.
Exploiting CVE-2016-8706 could allow an attacker to execute arbitrary code remotely on the server.