Re: Memcached.c Heap overflow in try_read_command

2017-06-27 Thread dormando
Hey, Thanks for the notice! I see you also sent one to me privately (I wasn't online much yesterday). Would've been nice to get a couple days heads up before a wide notice :) Looks like it's yet another binary protocol problem. I'm almost to the point where I'll be rewriting a lot of the

Memcached.c Heap overflow in try_read_command

2017-06-27 Thread daniel
Hi there, My name is Daniel and i am a security researcher @Twistlock As part of my job i am looking in to various open source projects that have container images and this is how i stumbled upon memcached. In memcached I've found a few weak points by reviewing the code,in particular there are