Lyon Yang discovered that the C client shells cli_st and cli_mt of Apache Zookeeper were affected by a buffer overflow vulnerability associated with parsing of the input command when using the "cmd:" batch mode syntax. If the command string exceeds 1024 characters a buffer overflow will occur (CVE-2016-5017).