memcached before 1.4.17 allows remote attackers to bypass authentication by sending an invalid request with SASL credentials, then sending another request with incorrect SASL credentials.
https://code.google.com/p/memcached/wiki/ReleaseNotes1417
http://www.ubuntu.com/usn/USN-2080-1
http://www.securityfocus.com/bid/64559
http://www.debian.org/security/2014/dsa-2832