PT-2016-3454 · Apache+2 · Apache Zookeeper+2

Published

2016-09-21

·

Updated

2024-08-15

·

CVE-2016-5017

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Zookeeper versions 3.4.9 and earlier, 3.5.x before 3.5.3
Description The issue is related to a buffer overflow in the C cli shell of Apache Zookeeper when using the "cmd:" batch mode syntax. This can allow attackers to have an impact on the confidentiality, integrity, and availability of protected information via a long command string. The vulnerability is associated with the parsing of the input command and can occur if the command string exceeds 1024 characters.
Recommendations For Apache Zookeeper versions 3.4.9 and earlier, update to version 3.4.9 or later. For Apache Zookeeper versions 3.5.x before 3.5.3, update to version 3.5.3 or later. As a temporary workaround, consider avoiding the use of the "cmd:" batch mode syntax in the C cli shell until a patch is available. Restrict access to the C cli shell to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-06489
CVE-2016-5017
DLA-630-1
MGASA-2016-0328
USN-4789-1

Affected Products

Apache Zookeeper
Red Os
Ubuntu