Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch mode syntax, allows attackers to have unspecified impact via a long command string.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade zookeeper | Mar 31, 2017 | Sep 18, 2016 |
| Ubuntu | — | Upgrade libzookeeper-mt2 (Ubuntu Pro)Upgrade libzookeeper-java (Ubuntu Pro)Upgrade zookeeper (Ubuntu Pro)Upgrade python-zookeeper (Ubuntu Pro)Upgrade libzookeeper2 (Ubuntu Pro)Upgrade zookeeperd (Ubuntu Pro)Upgrade zookeeper-bin (Ubuntu Pro)Upgrade libzookeeper-st2 (Ubuntu Pro) | Mar 22, 2023 | Sep 21, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub