Bug 1550066
| Summary: | memcached bind to all interfaces by default | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Andrey Bondarenko <abondare> |
| Component: | memcached | Assignee: | Miroslav Lichvar <mlichvar> |
| Status: | CLOSED WONTFIX | QA Contact: | qe-baseos-daemons |
| Severity: | high | Docs Contact: | |
| Priority: | medium | ||
| Version: | 7.4 | CC: | cperry, jonthompson, matthew.taylor, ondrejj, rschiron, thoger, thozza, yozone |
| Target Milestone: | rc | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2018-11-06 15:37:16 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Andrey Bondarenko
2018-02-28 12:42:48 UTC
*** Bug 1549752 has been marked as a duplicate of this bug. *** The trouble with changing the default config to listen only on the loopback interface is that it will break the service for users who need remote access and have not changed their config. Also, changing the default config will not work for users who have modified the file, but still allow remote access even when they don't need it. The security team will need to consider the change. FWIW, in the latest upstream code the UDP port is disabled by default. https://github.com/memcached/memcached/commit/dbb7a8af90054bf4ef51f5814ef7ceb17d83d974 As a side note, we have proposed an additional section in the RHEL Security Guide for future inclusion. This is tracked within https://bugzilla.redhat.com/show_bug.cgi?id=1550654 Cliff. memcached 1.5.6 release notes: https://github.com/memcached/memcached/wiki/ReleaseNotes156 Development Management has reviewed and declined this request. You may appeal this decision by reopening this request. |