Record summary

CVE-2016-8706 has a selected CVSS score of 8.1 (high); EIP currently links 1 Nuclei template.

Description

An integer overflow in process_bin_sasl_auth function in Memcached, which is responsible for authentication commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List1.4.31affected

Nuclei templates

1
ProjectDiscoveryHIGHMemcached Server SASL Authentication - Remote Code ExecutionCVSS 8.1

An integer overflow in process_bin_sasl_auth function in Memcached, which is responsible for authentication commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.

Impact

Attackers can trigger heap overflow in the SASL authentication function, potentially achieving remote code execution on Memcached servers.

Remediation

Upgrade Memcached to a version later than affected releases that properly handles integer overflow in SASL authentication.

WeaknessesCWE-190
Authorspussycat0x
Template tagscvecve2016rcejsmemcachedvuln
CVSS vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:memcached:memcached:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

7