Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w3r9-r9w7-8h48

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Golang Facebook Thrift servers vulnerable to denial of service

Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.

Specific Go Packages Affected

github.com/facebook/fbthrift/thrift/lib/go/thrift

Пакеты

Наименование

github.com/facebook/fbthrift

go
Затронутые версииВерсия исправления

< 0.31.1-0.20200311080807-483ed864d69f

0.31.1-0.20200311080807-483ed864d69f

EPSS

Процентиль: 73%
0.01557
Низкий

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.

CVSS3: 7.5
redhat
больше 6 лет назад

Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.

CVSS3: 7.5
nvd
больше 6 лет назад

Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.

msrc
21 день назад

Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.

EPSS

Процентиль: 73%
0.01557
Низкий

7.5 High

CVSS3

Дефекты

CWE-770