Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-5637

Опубликовано: 07 фев. 2017
Источник: redhat
CVSS3: 7.5

Описание

Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooKeeper thru version 3.4.9 and 3.5.2 suffer from this issue, fixed in 3.4.10, 3.5.3, and later.

A denial of service vulnerability was discovered in ZooKeeper which allows an attacker to dramatically increase CPU utilization by abusing "wchp/wchc" commands, leading to the server being unable to serve legitimate requests.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss A-MQ 6zookeeperWill not fix
Red Hat JBoss Fuse 6zookeeperWill not fix
Red Hat OpenShift Enterprise 2zookeeperUnder investigation
Red Hat JBoss BPMS 6.4zookeeperFixedRHSA-2017:335530.11.2017
Red Hat JBoss BRMS 6.4zookeeperFixedRHSA-2017:335430.11.2017
Red Hat JBoss Data Virtualization 6.3zookeeperFixedRHSA-2017:247715.08.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1454808zookeeper: Incorrect input validation with wchp/wchc four letter words

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooKeeper thru version 3.4.9 and 3.5.2 suffer from this issue, fixed in 3.4.10, 3.5.3, and later.

CVSS3: 7.5
nvd
больше 7 лет назад

Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooKeeper thru version 3.4.9 and 3.5.2 suffer from this issue, fixed in 3.4.10, 3.5.3, and later.

CVSS3: 7.5
debian
больше 7 лет назад

Two four letter word commands "wchp/wchc" are CPU intensive and could ...

CVSS3: 7.5
github
около 3 лет назад

Uncontrolled Resource Consumption in Apache ZooKeeper

CVSS3: 7.5
fstec
больше 8 лет назад

Уязвимость реализации команды wchp/wchc централизованной службы для поддержки информации о конфигурации, именования, обеспечения распределенной синхронизации и предоставления групповых служб Apache ZooKeeper, связанная с отсутствием аутентификации для критичной функции, позволяющая нарушителю, действующему удалённо, вызвать отказ в обслуживании

7.5 High

CVSS3