DirectorySecurity Advisories
Sign In
Security Advisories

CGA-ccj3-f4c8-28h3

Published

Last updated

https://images.chainguard.dev/security/CGA-ccj3-f4c8-28h3
Package

thrift

Latest Update
Not affected
Aliases
  • CVE-2019-11939
  • GHSA-w3r9-r9w7-8h48

Severity

7.5

High

CVSS V3

Summary

Golang Facebook Thrift servers vulnerable to denial of service

Description

Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.

Specific Go Packages Affected

github.com/facebook/fbthrift/thrift/lib/go/thrift

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images