CVE-2016-5017
published 2016-09-21CVE-2016-5017: Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch mode syntax, allows attackers to have…
PriorityP345high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
7.82%
94.0th percentile
Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch mode syntax, allows attackers to have unspecified impact via a long command string.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | zookeeper | <= 3.4.8 | — |
| apache | zookeeper | — | — |
| apache | zookeeper | — | — |
| apache | zookeeper | — | — |
| apache | zookeeper | >= 0 < 3.4.9-1 | 3.4.9-1 |
| apache | zookeeper | >= 0 < 3.4.9-1 | 3.4.9-1 |
| apache | zookeeper | >= 0 < 3.4.9-1 | 3.4.9-1 |
| apache | zookeeper | >= 0 < 3.4.9-1 | 3.4.9-1 |
| apache | zookeeper | >= 0 < 3.4.5+dfsg-1ubuntu0.1~esm1 | 3.4.5+dfsg-1ubuntu0.1~esm1 |
| apache | zookeeper | >= 0 < 3.4.8-1ubuntu0.1~esm1 | 3.4.8-1ubuntu0.1~esm1 |
| debian | zookeeper | < zookeeper 3.4.9-1 (bookworm) | zookeeper 3.4.9-1 (bookworm) |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
vendor_ubuntu8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-85r2-fvq8-6xw9: Buffer overflow in the C cli shell in Apache Zookeeper before 3
ghsa_unreviewed·2022-05-13
CVE-2016-5017 [HIGH] CWE-119 GHSA-85r2-fvq8-6xw9: Buffer overflow in the C cli shell in Apache Zookeeper before 3
Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch mode syntax, allows attackers to have unspecified impact via a long command string.
OSV
zookeeper vulnerabilities
osv·2021-03-15·CVSS 8.1
CVE-2016-5017 [HIGH] zookeeper vulnerabilities
zookeeper vulnerabilities
It was discovered that Apache ZooKeeper incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service or
other unspecified impact. (CVE-2016-5017)
It was discovered that Apache ZooKeeper incorrectly implemented "wchp/wchc"
commands. An attacker could possibly use this issue to cause a denial of
service. (CVE-2017-5637)
It was discovered that Apache Zookeeper incorrectly handled clusters. An
attacker could possibly use this issue to obtain sensitive information.
This issue only affected Ubuntu 16.04 ESM. (CVE-2018-8012)
OSV
CVE-2016-5017: Buffer overflow in the C cli shell in Apache Zookeeper before 3
osv·2016-09-21·CVSS 8.1
CVE-2016-5017 [HIGH] CVE-2016-5017: Buffer overflow in the C cli shell in Apache Zookeeper before 3
Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch mode syntax, allows attackers to have unspecified impact via a long command string.
Ubuntu
Apache ZooKeeper vulnerabilities
vendor_ubuntu·2021-03-15·CVSS 8.1
CVE-2017-5637 [HIGH] Apache ZooKeeper vulnerabilities
Title: Apache ZooKeeper vulnerabilities
Summary: Several security issues were fixed in Apache ZooKeeper.
It was discovered that Apache ZooKeeper incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service or
other unspecified impact. (CVE-2016-5017)
It was discovered that Apache ZooKeeper incorrectly implemented "wchp/wchc"
commands. An attacker could possibly use this issue to cause a denial of
service. (CVE-2017-5637)
It was discovered that Apache Zookeeper incorrectly handled clusters. An
attacker could possibly use this issue to obtain sensitive information.
This issue was only fixed in Ubuntu 16.04 ESM. (CVE-2018-8012)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
zookeeper: Buffer overflow vulnerability in C cli shell
vendor_redhat·2016-09-16·CVSS 8.1
CVE-2016-5017 [HIGH] CWE-122 zookeeper: Buffer overflow vulnerability in C cli shell
zookeeper: Buffer overflow vulnerability in C cli shell
Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch mode syntax, allows attackers to have unspecified impact via a long command string.
Package: zookeeper (Red Hat JBoss A-MQ 6) - Not affected
Package: zookeeper (Red Hat JBoss BRMS 6) - Not affected
Package: zookeeper (Red Hat JBoss Data Virtualization 6) - Not affected
Package: zookeeper (Red Hat JBoss Fuse 6) - Not affected
Package: zookeeper (Red Hat JBoss Fuse Service Works 6) - Not affected
Package: zookeeper (Red Hat OpenShift Enterprise 2) - Not affected
Debian
CVE-2016-5017: zookeeper - Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x be...
vendor_debian·2016·CVSS 8.1
CVE-2016-5017 [HIGH] CVE-2016-5017: zookeeper - Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x be...
Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch mode syntax, allows attackers to have unspecified impact via a long command string.
Scope: local
bookworm: resolved (fixed in 3.4.9-1)
bullseye: resolved (fixed in 3.4.9-1)
forky: resolved (fixed in 3.4.9-1)
sid: resolved (fixed in 3.4.9-1)
trixie: resolved (fixed in 3.4.9-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-5017 zookeeper: Buffer overflow vulnerability in C cli shell
bugzilla·2016-09-19·CVSS 8.1
CVE-2016-5017 [HIGH] CVE-2016-5017 zookeeper: Buffer overflow vulnerability in C cli shell
CVE-2016-5017 zookeeper: Buffer overflow vulnerability in C cli shell
The ZooKeeper C client shells "cli_st" and "cli_mt" have a buffer overflow vulnerability associated with parsing of the input command when using the "cmd:" batch mode syntax. If the command string exceeds 1024 characters a buffer overflow will occur. There is no known compromise which takes advantage of this vulnerability, and if security is enabled the attacker would be limited by client level security constraints. The C cli shell is intended as a sample/example of how to use the C client interface, not as a production tool - the documentation has also been clarified on this point.
References:
http://seclists.org/bugtraq/2016/Sep/29
Upstream fix:
https://git-wip-us.apache.org/repos/asf?p=zookeeper.git;a=commitdiff;
Bugzilla
CVE-2016-5017 zookeeper: Buffer overflow vulnerability in C cli shell [fedora-all]
bugzilla·2016-09-19·CVSS 8.1
CVE-2016-5017 [HIGH] CVE-2016-5017 zookeeper: Buffer overflow vulnerability in C cli shell [fedora-all]
CVE-2016-5017 zookeeper: Buffer overflow vulnerability in C cli shell [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
http://packetstormsecurity.com/files/138755/ZooKeeper-3.4.8-3.5.2-Buffer-Overflow.htmlhttp://www.openwall.com/lists/oss-security/2016/09/17/3http://www.securityfocus.com/bid/93044https://git-wip-us.apache.org/repos/asf?p=zookeeper.git%3Ba=commitdiff%3Bh=27ecf981a15554dc8e64a28630af7a5c9e2bdf4fhttps://git-wip-us.apache.org/repos/asf?p=zookeeper.git%3Ba=commitdiff%3Bh=f09154d6648eeb4ec5e1ac8a2bacbd2f8c87c14ahttps://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3Ehttps://lists.apache.org/thread.html/r4b743f407244294f316325458ccaabfce9cd70ca3a6423dbe574035c%40%3Cnotifications.dubbo.apache.org%3Ehttps://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3Ehttps://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://zookeeper.apache.org/security.html#CVE-2016-5017http://packetstormsecurity.com/files/138755/ZooKeeper-3.4.8-3.5.2-Buffer-Overflow.htmlhttp://www.openwall.com/lists/oss-security/2016/09/17/3http://www.securityfocus.com/bid/93044https://git-wip-us.apache.org/repos/asf?p=zookeeper.git%3Ba=commitdiff%3Bh=27ecf981a15554dc8e64a28630af7a5c9e2bdf4fhttps://git-wip-us.apache.org/repos/asf?p=zookeeper.git%3Ba=commitdiff%3Bh=f09154d6648eeb4ec5e1ac8a2bacbd2f8c87c14ahttps://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3Ehttps://lists.apache.org/thread.html/r4b743f407244294f316325458ccaabfce9cd70ca3a6423dbe574035c%40%3Cnotifications.dubbo.apache.org%3Ehttps://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3Ehttps://www.cloudera.com/documentation/other/security-bulletins/topics/csb_topic_1.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://zookeeper.apache.org/security.html#CVE-2016-5017
2016-09-21
Published