APP: Memcached process_bin_append_prepend Arbitrary Code Execution

This signature detects attempts to exploit a known vulnerability against memcached. Successful exploitation of the vulnerability can possibly lead to arbitrary code execution.

Extended Description

An integer overflow in the process_bin_append_prepend function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.

Affected Products

Memcached memcached

Short Name
APP:MISC:MEMCACHED-CE
Severity
Major
Recommended
True
Recommended Action
Drop
Category
APP
Keywords
Arbitrary CVE-2016-8704 CVE-2021-2389 Code Execution Memcached process_bin_append_prepend
Release Date
12/13/2016
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
Port
TCP/11211
False Positive
Unknown
Vendors

Memcached

CVSS Score

7.5

7.1

Found a potential security threat?