7.5
CVSSv3

CVE-2019-11939

Published: 18/03/2020 Updated: 20/03/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

facebook thrift

Vendor Advisories

Debian Bug report logs - #988948 CVE-2019-11939 Package: src:thrift; Maintainer for src:thrift is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Fri, 21 May 2021 19:51:01 UTC Severity: important Tags: security, upstream Reply or subscribe to this bug Toggle us ...