CVE-2017-5637
Summary
| CVE | CVE-2017-5637 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-10-10 01:30:00 UTC |
| Updated | 2023-11-07 02:49:00 UTC |
| Description | Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooKeeper thru version 3.4.9 and 3.5.2 suffer from this issue, fixed in 3.4.10, 3.5.3, and later. |
Risk And Classification
Problem Types: CWE-400 | CWE-306
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Zookeeper | 3.4.0 | All | All | All |
| Application | Apache | Zookeeper | 3.4.1 | All | All | All |
| Application | Apache | Zookeeper | 3.4.2 | All | All | All |
| Application | Apache | Zookeeper | 3.4.3 | All | All | All |
| Application | Apache | Zookeeper | 3.4.4 | All | All | All |
| Application | Apache | Zookeeper | 3.4.5 | All | All | All |
| Application | Apache | Zookeeper | 3.4.6 | All | All | All |
| Application | Apache | Zookeeper | 3.4.7 | All | All | All |
| Application | Apache | Zookeeper | 3.4.8 | All | All | All |
| Application | Apache | Zookeeper | 3.4.9 | All | All | All |
| Application | Apache | Zookeeper | 3.5.0 | All | All | All |
| Application | Apache | Zookeeper | 3.5.1 | All | All | All |
| Application | Apache | Zookeeper | 3.5.2 | All | All | All |
| Application | Apache | Zookeeper | 3.4.0 | All | All | All |
| Application | Apache | Zookeeper | 3.4.1 | All | All | All |
| Application | Apache | Zookeeper | 3.4.2 | All | All | All |
| Application | Apache | Zookeeper | 3.4.3 | All | All | All |
| Application | Apache | Zookeeper | 3.4.4 | All | All | All |
| Application | Apache | Zookeeper | 3.4.5 | All | All | All |
| Application | Apache | Zookeeper | 3.4.6 | All | All | All |
| Application | Apache | Zookeeper | 3.4.7 | All | All | All |
| Application | Apache | Zookeeper | 3.4.8 | All | All | All |
| Application | Apache | Zookeeper | 3.4.9 | All | All | All |
| Application | Apache | Zookeeper | 3.5.0 | All | All | All |
| Application | Apache | Zookeeper | 3.5.1 | All | All | All |
| Application | Apache | Zookeeper | 3.5.2 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Oracle Critical Patch Update Advisory - July 2020 | MISC | www.oracle.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Oracle Critical Patch Update Advisory - July 2021 | N/A | www.oracle.com | |
| Debian -- Security Information -- DSA-3871-1 zookeeper | DEBIAN | www.debian.org | Third Party Advisory |
| [ZOOKEEPER-2693] DOS attack on wchp/wchc four letter words (4lw) - ASF JIRA | CONFIRM | issues.apache.org | Issue Tracking, Mitigation, Vendor Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Pony Mail! | lists.apache.org | ||
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Pony Mail! | lists.apache.org | ||
| Apache Mail Archives | lists.apache.org | ||
| Apache Mail Archives | MLIST | lists.apache.org | Mailing List, Vendor Advisory |
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | lists.apache.org | ||
| Malformed Request | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.