Back to Vulnerability Directory
HIGHFixed upstream

CVE-2016-5017

Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when…

Technology

Apache ZooKeeper

CVSS Score

8.1 / 10.0

Affected Versions

<=3.4.8; 3.5.0; 3.5.1; 3.5.2

Upstream Fix

See upstream advisory

Published

September 21, 2016

OSSeva Coverage

Fixed upstream

Description

Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch mode syntax, allows attackers to have unspecified impact via a long command string.

Is your Apache ZooKeeper deployment affected?

If you're running <=3.4.8; 3.5.0; 3.5.1; 3.5.2, you need this patch. Book a discovery call to get covered.