DSA-3871Vendor advisory
http://www.debian.org/security/2017/dsa-3871 CVE-2017-5637
HIGH
Uncontrolled Resource Consumption in Apache ZooKeeper
Record summary
CVE-2017-5637 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooKeeper thru version 3.4.9 and 3.5.2 suffer from this issue, fixed in 3.4.10, 3.5.3, and later.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Apache ZooKeeperBrowse Apache Software Foundation / Apache ZooKeeper | CVE List | 3.4.0 to 3.4.9 | affected |
| 3.5.0 to 3.5.2 | affected | ||
org.apache.zookeeper:zookeeperBrowse Maven / org.apache.zookeeper:zookeeper | GitHub Advisory | 3.4.0 to < 3.4.10 · Fixed in 3.4.10 | affected |
| 3.5.0 to < 3.5.3 · Fixed in 3.5.3 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBZookeeper 3.5.2 Client - Denial of ServiceExploitDB exploitby Brandon DennisNot analyzed1 file
References
Showing 12 of 1798814vdb entry
http://www.securityfocus.com/bid/98814 RHSA-2017:2477Vendor advisory
https://access.redhat.com/errata/RHSA-2017:2477 RHSA-2017:3354Vendor advisory
https://access.redhat.com/errata/RHSA-2017:3354 RHSA-2017:3355Vendor advisory
https://access.redhat.com/errata/RHSA-2017:3355 issues.apache.orgConfirmation
https://issues.apache.org/jira/browse/ZOOKEEPER-2693 [activemq-issues] 20190820 [jira] [Created] (AMQ-7279) Security Vulnerabilities in Libraries - jackson-databind-2.9.8.jar, tomcat-servlet-api-8.0.53.jar, tomcat-websocket-api-8.0.53.jar, zookeeper-3.4.6.jar, guava-18.0.jar, jetty-all-9.2.26.v20180806.jar, scala-library-2.11.0.jarmailing list
https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272%40%3Cissues.activemq.apache.org%3E lists.apache.org
https://lists.apache.org/thread.html/053d9ce4d579b02203db18545fee5e33f35f2932885459b74d1e4272@%3Cissues.activemq.apache.org%3E [dev] 20171009 [SECURITY] CVE-2017-5637: DOS attack on wchp/wchc four letter words (4lw)mailing list
https://lists.apache.org/thread.html/58170aeb7a681d462b7fa31cae81110cbb749d2dc83c5736a0bb8370%40%3Cdev.zookeeper.apache.org%3E lists.apache.org
https://lists.apache.org/thread.html/58170aeb7a681d462b7fa31cae81110cbb749d2dc83c5736a0bb8370@%3Cdev.zookeeper.apache.org%3E [nifi-commits] 20191113 svn commit: r1869773 - /nifi/site/trunk/security.htmlmailing list
https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E lists.apache.org
https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E