Rule Category

SERVER-OTHER -- Snort has detected traffic exploiting vulnerabilities in a server in the network.

Alert Message

SERVER-OTHER Memcached SASL auth opcode request heap buffer overflow attempt

Rule Explanation

This event is generated when a Memcached SASL auth opcode request heap buffer overflow is detected Impact: CVSS base score 8.1 CVSS impact score 5.9 CVSS exploitability score 2.2 confidentialityImpact HIGH integrityImpact HIGH availabilityImpact HIGH CVE-2016-8706: CVSS base score 8.1 CVSS impact score 5.9 CVSS exploitability score 2.2 Confidentiality Impact HIGH Integrity Impact HIGH Availability Impact HIGH Details: CVE-2016-8706: An integer overflow in processbinsasl_auth function in Memcached, which is responsible for authentication commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution. Ease of Attack: CVE-2016-8706: Access Vector Access Complexity Authentication

What To Look For

No information provided

Known Usage

No public information

False Positives

No known false positives

Contributors

Cisco Talos Intelligence Group

Rule Groups

No rule groups

CVE

Additional Links

Rule Vulnerability

CVE Additional Information

This product uses data from the NVD API but is not endorsed or certified by the NVD.
CVE-2016-8706
Loading description