Description
Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5486 | Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00. |
Github GHSA |
GHSA-w3r9-r9w7-8h48 | Golang Facebook Thrift servers vulnerable to denial of service |
References
History
No history.
Status: PUBLISHED
Assigner: facebook
Published:
Updated: 2024-08-04T23:10:29.633Z
Reserved: 2019-05-13T00:00:00.000Z
Link: CVE-2019-11939
No data.
Status : Modified
Published: 2020-03-18T01:15:11.660
Modified: 2024-11-21T04:22:01.407
Link: CVE-2019-11939
OpenCVE Enrichment
No data.
EUVD
Github GHSA