Debian DSA-2832-1 : memcached - several vulnerabilities

medium Nessus Plugin ID 71780

Synopsis

The remote Debian host is missing a security-related update.

Description

Multiple vulnerabilities have been found in memcached, a high-performance memory object caching system. The Common Vulnerabilities and Exposures project identifies the following issues :

- CVE-2011-4971 Stefan Bucur reported that memcached could be caused to crash by sending a specially crafted packet.

- CVE-2013-7239 It was reported that SASL authentication could be bypassed due to a flaw related to the managment of the SASL authentication state. With a specially crafted request, a remote attacker may be able to authenticate with invalid SASL credentials.

Solution

Upgrade the memcached packages.

For the oldstable distribution (squeeze), these problems have been fixed in version 1.4.5-1+deb6u1. Note that the patch for CVE-2013-7239 was not applied for the oldstable distribution as SASL support is not enabled in this version. This update also provides the fix for CVE-2013-0179 which was fixed for stable already.

For the stable distribution (wheezy), these problems have been fixed in version 1.4.13-0.2+deb7u1.

See Also

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=706426

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=733643

https://security-tracker.debian.org/tracker/CVE-2011-4971

https://security-tracker.debian.org/tracker/CVE-2013-7239

https://security-tracker.debian.org/tracker/CVE-2013-0179

https://packages.debian.org/source/squeeze/memcached

https://packages.debian.org/source/wheezy/memcached

https://www.debian.org/security/2014/dsa-2832

Plugin Details

Severity: Medium

ID: 71780

File Name: debian_DSA-2832.nasl

Version: 1.11

Type: local

Agent: unix

Published: 1/2/2014

Updated: 1/11/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.7

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:memcached, cpe:/o:debian:debian_linux:6.0, cpe:/o:debian:debian_linux:7.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Ease: No known exploits are available

Patch Publication Date: 1/1/2014

Reference Information

CVE: CVE-2011-4971, CVE-2013-7239

BID: 59567, 64559

DSA: 2832