It was reported [1] that PHPMemcachedAdmin, a web-based frontend for Linux's memcached Daemon, is vulnerable to a remote code execution flaw: ----- PHPMemcachedAdmin stores data in the server's filesystem. Part of the serialized data and the last part of the concatenated filename may be specified by the user, which can lead to remote code execution e.g. if a php script is created and placed within the webserver's document root. All versions prior and including the current version 1.2.2 are affected as far as we know. ----- Upstream has been contacted about this issue and a patch is being worked on [2]. [1] http://seclists.org/bugtraq/2014/Nov/71 [2] http://seclists.org/bugtraq/2014/Nov/76
Created phpMemcachedAdmin tracking bugs for this issue: Affects: fedora-all [bug 1163790] Affects: epel-6 [bug 1163791]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.