Bug#868701: memcached: CVE-2017-9951: Heap-based buffer over-read in try_read_command function

2017-07-25 Thread Salvatore Bonaccorso
Hi Guillaume! On Tue, Jul 25, 2017 at 01:16:26AM +0200, Guillaume Delacour wrote: > On Mon, Jul 17, 2017 at 10:34:23PM +0200, Salvatore Bonaccorso wrote: > > Please adjust the affected versions in the BTS as needed. > > > > Please find attached the debdiff for Debian 9 Stretch. > Also, you can

Bug#868701: memcached: CVE-2017-9951: Heap-based buffer over-read in try_read_command function

2017-07-24 Thread Guillaume Delacour
On Mon, Jul 17, 2017 at 10:34:23PM +0200, Salvatore Bonaccorso wrote: > Please adjust the affected versions in the BTS as needed. > Please find attached the debdiff for Debian 9 Stretch. Also, you can find a little test case (and results) without (CVE-2017-9951_1.4.33.log) and with the fix

Bug#868701: memcached: CVE-2017-9951: Heap-based buffer over-read in try_read_command function

2017-07-24 Thread Guillaume Delacour
On Mon, Jul 17, 2017 at 10:34:23PM +0200, Salvatore Bonaccorso wrote: > > Please adjust the affected versions in the BTS as needed. Please find attached the debdiff for Debian 8 Jessie. Also, you can find a little test case (and results) without (CVE-2017-9951_exploit.log) and with the fix

Bug#868701: memcached: CVE-2017-9951: Heap-based buffer over-read in try_read_command function

2017-07-17 Thread Salvatore Bonaccorso
Source: memcached Version: 1.4.33-1 Severity: important Tags: security upstream Hi, the following vulnerability was published for memcached. CVE-2017-9951[0]: | The try_read_command function in memcached.c in memcached before 1.4.39 | allows remote attackers to cause a denial of service