[Bug 1255328] Re: Installing memcached package creates /nonexistent

Launchpad Bug Tracker 1255328 at bugs.launchpad.net
Mon Jan 13 21:58:20 UTC 2014


This bug was fixed in the package memcached - 1.4.14-0ubuntu9

---------------
memcached (1.4.14-0ubuntu9) trusty; urgency=low

  * SECURITY UPDATE: denial of service via large body length
    - debian/patches/CVE-2011-4971.patch: check length in memcached.c,
      added test to t/issue_192.t.
    - CVE-2011-4971
  * SECURITY UPDATE: denial of service when using -vv
    - debian/patches/CVE-2013-0179.patch: properly format key in items.c,
      memcached.c.
    - CVE-2013-0179
  * SECURITY UPDATE: SASL authentication bypass
    - debian/patches/CVE-2013-7239.patch: explicitly record sasl auth
      states in memcached.*, added test to t/binary-sasl.t.
    - CVE-2013-7239
  * debian/memcached.postinst: don't create home directory so we don't end
    up with /nonexistent. Thanks to Dustin Lundquist for patch.
    (LP: #1255328)
 -- Marc Deslauriers <marc.deslauriers at ubuntu.com>   Mon, 13 Jan 2014 15:48:48 -0500

** Changed in: memcached (Ubuntu)
       Status: Confirmed => Fix Released

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2011-4971

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2013-0179

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2013-7239

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to memcached in Ubuntu.
https://bugs.launchpad.net/bugs/1255328

Title:
  Installing memcached package creates /nonexistent

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/memcached/+bug/1255328/+subscriptions



More information about the Ubuntu-server-bugs mailing list