Description
Java Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.12.09.00.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-3595 | Java Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.12.09.00. |
References
History
No history.
Status: PUBLISHED
Assigner: facebook
Published:
Updated: 2024-08-04T23:10:29.610Z
Reserved: 2019-05-13T00:00:00.000Z
Link: CVE-2019-11938
No data.
Status : Modified
Published: 2020-03-10T21:15:11.653
Modified: 2024-11-21T04:22:01.290
Link: CVE-2019-11938
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD