First published: Wed Sep 21 2016(Updated: )
Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch mode syntax, allows attackers to have unspecified impact via a long command string.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache ZooKeeper | <=3.4.8 | |
Apache ZooKeeper | =3.5.0 | |
Apache ZooKeeper | =3.5.1 | |
Apache ZooKeeper | =3.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5017 is considered a critical vulnerability due to its potential to allow attackers to exploit buffer overflow conditions.
To fix CVE-2016-5017, upgrade Apache ZooKeeper to version 3.4.9 or 3.5.3 or later.
CVE-2016-5017 affects Apache ZooKeeper versions prior to 3.4.9 and 3.5.x before 3.5.3.
CVE-2016-5017 can lead to undefined behavior in the Apache ZooKeeper service, potentially allowing unauthorized command execution.
Check the version of your Apache ZooKeeper installation against the affected versions listed for CVE-2016-5017.