Bug 817781 (CVE-2011-4971) - VUL-1: memcached: CVE-2011-4971: remote DoS
Summary: VUL-1: memcached: CVE-2011-4971: remote DoS
Status: RESOLVED FIXED
Alias: CVE-2011-4971
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: CVSSv2:SUSE:CVE-2011-4971:1.8:(AV:A/A...
Keywords:
Depends on:
Blocks:
 
Reported: 2013-04-30 06:36 UTC by Sebastian Krahmer
Modified: 2020-06-18 02:31 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sebastian Krahmer 2013-04-30 06:36:16 UTC
Via OSS-sec:

Date: Mon, 29 Apr 2013
From: Kurt Seifried
To: Open Source Security


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

So this was brought to my attention:

http://insecurety.net/?p=872

Memcached remote DoS (segmentation fault)

Works like a charm on Fedora 18 running Memcached 1.4.15 (the latest
stable).

Please use CVE-2013-2026 for this issue. I guess the good news is that
because memcached basically has no security most people run it within
closed networks, hopefully no-one is running these things publicly
like a lot of people used to (http://www.sensepost.com/blog/4873.html).


- --
Kurt Seifried Red Hat Security Response Team (SRT)
PGP: 0x5E267993 A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993
Comment 1 Sebastian Krahmer 2013-04-30 06:37:28 UTC
Wrong CVE.

Use CVE-2011-4971
Comment 3 Swamp Workflow Management 2013-04-30 22:00:22 UTC
bugbot adjusting priority
Comment 4 Bernhard Wiedemann 2014-06-25 14:00:22 UTC
This is an autogenerated message for OBS integration:
This bug (817781) was mentioned in
https://build.opensuse.org/request/show/238633 13.1+12.3 / memcached
Comment 5 Swamp Workflow Management 2014-07-03 14:04:47 UTC
openSUSE-SU-2014:0867-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 798458,817781,857188,858676,858677
CVE References: CVE-2011-4971,CVE-2013-0179,CVE-2013-7239,CVE-2013-7290,CVE-2013-7291
Sources used:
openSUSE 13.1 (src):    memcached-1.4.20-6.4.1
openSUSE 12.3 (src):    memcached-1.4.20-3.4.1
Comment 6 Marcus Rückert 2014-07-07 15:14:34 UTC
those are the only bugs that still need some fixing on sle 11.
Comment 7 Swamp Workflow Management 2014-07-30 18:48:14 UTC
openSUSE-SU-2014:0951-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 798458,817781,857188,858676,858677
CVE References: CVE-2011-4971,CVE-2013-0179,CVE-2013-7239,CVE-2013-7290,CVE-2013-7291
Sources used:
openSUSE 11.4 (src):    memcached-1.4.20-7.1
Comment 8 Marcus Meissner 2016-03-23 08:12:29 UTC
lets consider it done
Comment 9 Swamp Workflow Management 2018-03-22 16:28:56 UTC
SUSE-SU-2018:0778-1: An update that fixes 9 vulnerabilities is now available.

Category: security (important)
Bug References: 1007869,1007870,1007871,1056865,798458,817781,857188,858676,858677
CVE References: CVE-2011-4971,CVE-2013-0179,CVE-2013-7239,CVE-2013-7290,CVE-2013-7291,CVE-2016-8704,CVE-2016-8705,CVE-2016-8706,CVE-2017-9951
Sources used:
SUSE OpenStack Cloud 7 (src):    memcached-1.4.39-3.3.2
SUSE Enterprise Storage 4 (src):    memcached-1.4.39-3.3.2
Comment 10 Swamp Workflow Management 2018-03-26 13:10:38 UTC
SUSE-SU-2018:0807-1: An update that fixes 9 vulnerabilities is now available.

Category: security (important)
Bug References: 1007869,1007870,1007871,1056865,798458,817781,857188,858676,858677
CVE References: CVE-2011-4971,CVE-2013-0179,CVE-2013-7239,CVE-2013-7290,CVE-2013-7291,CVE-2016-8704,CVE-2016-8705,CVE-2016-8706,CVE-2017-9951
Sources used:
SUSE OpenStack Cloud 6 (src):    memcached-1.4.39-3.3.1