memcached: CVE-2019-11596

Related Vulnerabilities: CVE-2019-11596  

Debian Bug report logs - #928205
memcached: CVE-2019-11596

version graph

Reported by: Salvatore Bonaccorso <carnil@debian.org>

Date: Mon, 29 Apr 2019 20:30:01 UTC

Severity: important

Tags: fixed-upstream, patch, security, upstream

Found in version memcached/1.5.6-1

Fixed in version memcached/1.5.6-1.1

Done: Salvatore Bonaccorso <carnil@debian.org>

Bug is archived. No further changes may be made.

Forwarded to https://github.com/memcached/memcached/issues/474

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, carnil@debian.org, team@security.debian.org, team@security.debian.org, Guillaume Delacour <gui@iroqwa.org>:
Bug#928205; Package src:memcached. (Mon, 29 Apr 2019 20:30:03 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
New Bug report received and forwarded. Copy sent to carnil@debian.org, team@security.debian.org, team@security.debian.org, Guillaume Delacour <gui@iroqwa.org>. (Mon, 29 Apr 2019 20:30:03 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: memcached: CVE-2019-11596
Date: Mon, 29 Apr 2019 22:27:04 +0200
Source: memcached
Version: 1.5.6-1
Severity: important
Tags: security upstream
Forwarded: https://github.com/memcached/memcached/issues/474

Hi,

The following vulnerability was published for memcached.

CVE-2019-11596[0]:
| In memcached before 1.5.14, a NULL pointer dereference was found in
| the "lru mode" and "lru temp_ttl" commands. This causes a denial of
| service when parsing crafted lru command messages in
| process_lru_command in memcached.c.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2019-11596
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11596
[1] https://github.com/memcached/memcached/issues/474
[2] https://github.com/memcached/memcached/commit/d35334f368817a77a6bd1f33c6a5676b2c402c02

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



Information forwarded to debian-bugs-dist@lists.debian.org, Guillaume Delacour <gui@iroqwa.org>:
Bug#928205; Package src:memcached. (Sun, 05 May 2019 13:36:03 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
Extra info received and forwarded to list. Copy sent to Guillaume Delacour <gui@iroqwa.org>. (Sun, 05 May 2019 13:36:03 GMT) (full text, mbox, link).


Message #10 received at 928205@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: 928205@bugs.debian.org
Subject: memcached: diff for NMU version 1.5.6-1.1
Date: Sun, 5 May 2019 15:34:04 +0200
[Message part 1 (text/plain, inline)]
Control: tags 928205 + patch
Control: tags 928205 + pending


Dear maintainer,

I've prepared an NMU for memcached (versioned as 1.5.6-1.1) and
uploaded it to DELAYED/5. Please feel free to tell me if I
should delay it longer.

Regards,
Salvatore
[memcached-1.5.6-1.1-nmu.diff (text/x-diff, attachment)]

Added tag(s) patch. Request was from Salvatore Bonaccorso <carnil@debian.org> to 928205-submit@bugs.debian.org. (Sun, 05 May 2019 13:36:03 GMT) (full text, mbox, link).


Added tag(s) pending. Request was from Salvatore Bonaccorso <carnil@debian.org> to 928205-submit@bugs.debian.org. (Sun, 05 May 2019 13:36:04 GMT) (full text, mbox, link).


Added tag(s) fixed-upstream. Request was from debian-bts-link@lists.debian.org to control@bugs.debian.org. (Mon, 06 May 2019 19:30:14 GMT) (full text, mbox, link).


Reply sent to Salvatore Bonaccorso <carnil@debian.org>:
You have taken responsibility. (Fri, 10 May 2019 14:36:06 GMT) (full text, mbox, link).


Notification sent to Salvatore Bonaccorso <carnil@debian.org>:
Bug acknowledged by developer. (Fri, 10 May 2019 14:36:06 GMT) (full text, mbox, link).


Message #21 received at 928205-close@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: 928205-close@bugs.debian.org
Subject: Bug#928205: fixed in memcached 1.5.6-1.1
Date: Fri, 10 May 2019 14:35:09 +0000
Source: memcached
Source-Version: 1.5.6-1.1

We believe that the bug you reported is fixed in the latest version of
memcached, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 928205@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Salvatore Bonaccorso <carnil@debian.org> (supplier of updated memcached package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 05 May 2019 13:36:30 +0200
Source: memcached
Architecture: source
Version: 1.5.6-1.1
Distribution: unstable
Urgency: medium
Maintainer: Guillaume Delacour <gui@iroqwa.org>
Changed-By: Salvatore Bonaccorso <carnil@debian.org>
Closes: 928205
Changes:
 memcached (1.5.6-1.1) unstable; urgency=medium
 .
   * Non-maintainer upload.
   * Fix NULL pointer dereference in the "lru mode" and "lru temp_ttl" commands
     (CVE-2019-11596) (Closes: #928205)
Checksums-Sha1: 
 440aed104c0a392cc84933bfecea7052ddc57dfb 2103 memcached_1.5.6-1.1.dsc
 d308e4fbc94ed502f9e3eebe46dca92ce0c388a0 14276 memcached_1.5.6-1.1.debian.tar.xz
Checksums-Sha256: 
 208078951caf85afee362c30bb16843aca8bbb3c458d235f38c136e40072b28a 2103 memcached_1.5.6-1.1.dsc
 1ab61dca83c5cbc7e7a6aaecfeb37684556316cf689523eee9e001e328a7c946 14276 memcached_1.5.6-1.1.debian.tar.xz
Files: 
 124b4e0ad39cb85c80b3ee52b7da8e06 2103 web optional memcached_1.5.6-1.1.dsc
 48e4c0cc7b3c095571eadf823b670239 14276 web optional memcached_1.5.6-1.1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAlzO5elfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89ErCsP/3wqNZd3Y0vq5F7iM4qTkbrNG88E6ERz
TwZ4LN9SL8reOgyF3KAXJHLJMiGXyo1vykSZhzdzQSyGIBYo2C3vDym/hmal3SNI
l3nGQLj5aQA+6PwfBSkWLvgGFlSY5RyeMTgoHAdL/m6NzAZzHIJsh5jq3NieOKd/
nnItFfbi2M9T/X/Qssm4W9yLdbixWuxvghIBwIFPfKPUFHDeuw2rc6wWL++qJKMg
lFTQIFWUf8lFeJHb0UgwjCVSyDiElSZR90ib8uSJQl3MM7Xtp8mzdhSzHTIu47Q9
9VBNVwdSFXgP75fvDiEZKEkG+h/kJklx1G68jXLV3kJhSpRAhVvo4Bat+28ERciK
bXE6ENOpV2DXInBxFiaGaMIlrFRHjDlNb72BHkoQz0MrCoG+7saeXbI3+q3wdEfv
G/47WGTixTX3+cLO9rcswTylNoyoyjWLCc+DqlmVchwbvYY4UCduFBvQrt0WRw/8
giazIImvQT/E6+lLMwfh7zzKtpAGRHp9QnKXEgn2c+1qEgRUhXB9rkhjp5OZN/d5
AtMfHEhpd1XYi68CBfbWUVtth47xDMuW9zCXSYyBHaY5uLDy3FgDd245P4D3uWtR
JmJD9CDKuDX3/eiLmyWeY4pMcLvMO7w6EkRIOUMyY5FBstwidGjtEsDOkIu+7DTR
pKXQ9slwbPuN
=HPRi
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Mon, 10 Jun 2019 07:25:07 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 19:02:35 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.