CVE-2019-3564
Expert Analysis
Professional remediation guidance
Get tailored security recommendations from our analyst team for CVE-2019-3564. We'll provide specific mitigation strategies based on your environment and risk profile.
Description
Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.03.04.00.
Available Exploits
Related News
Affected Products
Affected Versions:
GitHub Security Advisories
Community-driven vulnerability intelligence from GitHub
Improper Input Validation and Excessive Iteration in Go Facebook Thrift
GHSA-x4rg-4545-4w7wAdvisory Details
Affected Packages
CVSS Scoring
CVSS Score
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References
Advisory provided by GitHub Security Advisory Database. Published: February 15, 2022, Modified: November 3, 2021