USN-4789-1: Apache ZooKeeper vulnerabilities
15 March 2021
Several security issues were fixed in Apache ZooKeeper.
Releases
Packages
- zookeeper - High-performance coordination service for distributed application
Details
It was discovered that Apache ZooKeeper incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service or
other unspecified impact. (CVE-2016-5017)
It was discovered that Apache ZooKeeper incorrectly implemented "wchp/wchc"
commands. An attacker could possibly use this issue to cause a denial of
service. (CVE-2017-5637)
It was discovered that Apache Zookeeper incorrectly handled clusters. An
attacker could possibly use this issue to obtain sensitive information.
This issue was only fixed in Ubuntu 16.04 ESM. (CVE-2018-8012)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.04
-
libzookeeper-java
-
3.4.8-1ubuntu0.1~esm1
Available with Ubuntu Pro
-
libzookeeper2
-
3.4.8-1ubuntu0.1~esm1
Available with Ubuntu Pro
-
libzookeeper-st2
-
3.4.8-1ubuntu0.1~esm1
Available with Ubuntu Pro
-
zookeeper
-
3.4.8-1ubuntu0.1~esm1
Available with Ubuntu Pro
-
zookeeperd
-
3.4.8-1ubuntu0.1~esm1
Available with Ubuntu Pro
-
zookeeper-bin
-
3.4.8-1ubuntu0.1~esm1
Available with Ubuntu Pro
-
libzookeeper-mt2
-
3.4.8-1ubuntu0.1~esm1
Available with Ubuntu Pro
-
python-zookeeper
-
3.4.8-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 14.04
-
libzookeeper-java
-
3.4.5+dfsg-1ubuntu0.1~esm1
Available with Ubuntu Pro
-
libzookeeper2
-
3.4.5+dfsg-1ubuntu0.1~esm1
Available with Ubuntu Pro
-
libzookeeper-st2
-
3.4.5+dfsg-1ubuntu0.1~esm1
Available with Ubuntu Pro
-
zookeeper
-
3.4.5+dfsg-1ubuntu0.1~esm1
Available with Ubuntu Pro
-
zookeeperd
-
3.4.5+dfsg-1ubuntu0.1~esm1
Available with Ubuntu Pro
-
zookeeper-bin
-
3.4.5+dfsg-1ubuntu0.1~esm1
Available with Ubuntu Pro
-
libzookeeper-mt2
-
3.4.5+dfsg-1ubuntu0.1~esm1
Available with Ubuntu Pro
-
python-zookeeper
-
3.4.5+dfsg-1ubuntu0.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.