File _patchinfo of Package patchinfo.11123
<patchinfo incident="11123"> <issue tracker="cve" id="2019-11596"/> <issue tracker="cve" id="2019-15026"/> <issue tracker="bnc" id="1133817">VUL-1: CVE-2019-11596: memcached: In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This causes a denial of service when parsing crafted lru command messages in process_lru_comma</issue> <issue tracker="bnc" id="1149110">VUL-1: CVE-2019-15026: memcached: stack-based buffer over-read in conn_to_str in memcached.c</issue> <packager>pgajdos</packager> <rating>moderate</rating> <category>security</category> <summary>Security update for memcached</summary> <description>This update for memcached fixes the following issues: Security issue fixed: - CVE-2019-11596: Fixed a NULL pointer dereference in process_lru_command (bsc#1133817). - CVE-2019-15026: Fixed a stack-based buffer over-read (bsc#1149110). </description> </patchinfo>