CVE-2016-5017: Buffer Overflow
Published Sep 21, 2016
·Updated
Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch mode syntax, allows attackers to have unspecified impact via a long command string.
Affected Software
4 affected components
Apache Zookeeper<=3.4.8
Apache Zookeeper=3.5.0
Apache Zookeeper=3.5.1
Apache Zookeeper=3.5.2
Remediation
Event History
Sep 21, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5017?
CVE-2016-5017 is considered a critical vulnerability due to its potential to allow attackers to exploit buffer overflow conditions.
2
How do I fix CVE-2016-5017?
To fix CVE-2016-5017, upgrade Apache ZooKeeper to version 3.4.9 or 3.5.3 or later.
3
What systems are affected by CVE-2016-5017?
CVE-2016-5017 affects Apache ZooKeeper versions prior to 3.4.9 and 3.5.x before 3.5.3.
4
What impact can CVE-2016-5017 have on my systems?
CVE-2016-5017 can lead to undefined behavior in the Apache ZooKeeper service, potentially allowing unauthorized command execution.
5
How can I determine if my ZooKeeper installation is vulnerable to CVE-2016-5017?
Check the version of your Apache ZooKeeper installation against the affected versions listed for CVE-2016-5017.