/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2019-11938

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2019-11938

CGA ID

CGA-xqc8-8jj2-43mm

Severity

7.5

High

CVSS V3

Description

Java Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.12.09.00.

References

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images