Bugzilla – Bug 817781
VUL-1: memcached: CVE-2011-4971: remote DoS
Last modified: 2020-06-18 02:31:18 UTC
Via OSS-sec: Date: Mon, 29 Apr 2013 From: Kurt Seifried To: Open Source Security -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 So this was brought to my attention: http://insecurety.net/?p=872 Memcached remote DoS (segmentation fault) Works like a charm on Fedora 18 running Memcached 1.4.15 (the latest stable). Please use CVE-2013-2026 for this issue. I guess the good news is that because memcached basically has no security most people run it within closed networks, hopefully no-one is running these things publicly like a lot of people used to (http://www.sensepost.com/blog/4873.html). - -- Kurt Seifried Red Hat Security Response Team (SRT) PGP: 0x5E267993 A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993
Wrong CVE. Use CVE-2011-4971
bugbot adjusting priority
This is an autogenerated message for OBS integration: This bug (817781) was mentioned in https://build.opensuse.org/request/show/238633 13.1+12.3 / memcached
openSUSE-SU-2014:0867-1: An update that fixes 5 vulnerabilities is now available. Category: security (moderate) Bug References: 798458,817781,857188,858676,858677 CVE References: CVE-2011-4971,CVE-2013-0179,CVE-2013-7239,CVE-2013-7290,CVE-2013-7291 Sources used: openSUSE 13.1 (src): memcached-1.4.20-6.4.1 openSUSE 12.3 (src): memcached-1.4.20-3.4.1
those are the only bugs that still need some fixing on sle 11.
openSUSE-SU-2014:0951-1: An update that fixes 5 vulnerabilities is now available. Category: security (moderate) Bug References: 798458,817781,857188,858676,858677 CVE References: CVE-2011-4971,CVE-2013-0179,CVE-2013-7239,CVE-2013-7290,CVE-2013-7291 Sources used: openSUSE 11.4 (src): memcached-1.4.20-7.1
lets consider it done
SUSE-SU-2018:0778-1: An update that fixes 9 vulnerabilities is now available. Category: security (important) Bug References: 1007869,1007870,1007871,1056865,798458,817781,857188,858676,858677 CVE References: CVE-2011-4971,CVE-2013-0179,CVE-2013-7239,CVE-2013-7290,CVE-2013-7291,CVE-2016-8704,CVE-2016-8705,CVE-2016-8706,CVE-2017-9951 Sources used: SUSE OpenStack Cloud 7 (src): memcached-1.4.39-3.3.2 SUSE Enterprise Storage 4 (src): memcached-1.4.39-3.3.2
SUSE-SU-2018:0807-1: An update that fixes 9 vulnerabilities is now available. Category: security (important) Bug References: 1007869,1007870,1007871,1056865,798458,817781,857188,858676,858677 CVE References: CVE-2011-4971,CVE-2013-0179,CVE-2013-7239,CVE-2013-7290,CVE-2013-7291,CVE-2016-8704,CVE-2016-8705,CVE-2016-8706,CVE-2017-9951 Sources used: SUSE OpenStack Cloud 6 (src): memcached-1.4.39-3.3.1