RULE(RULE ID:710622)

Rule General Information
Release Date: 2019-11-12
Rule Name: Memcached process_bin_update body_len Integer Overflow Vulnerability -3 (CVE-2016-8705)
Severity:
CVE ID:
Rule Protection Details
Description: Multiple integer overflows in process_bin_update function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.
Impact: An attacker can exploit the affected software with a integer overflow vulnerability. Successful exploit leads to execute arbitrary code, and failed exploit may disturb the software logic and cause denial of service.
Affected OS: Mac OS, Solaris, Other Unix, FreeBSD, Linux
Reference: SecurityFocusBID:94083
http://rhn.redhat.com/errata/RHSA-2016-2819.html
http://rhn.redhat.com/errata/RHSA-2016-2820.html
http://www.debian.org/security/2016/dsa-3704
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://github.com/memcached/memcached/wiki/ReleaseNotes1433