Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w3r9-r9w7-8h48

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Golang Facebook Thrift servers vulnerable to denial of service

Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.

Specific Go Packages Affected

github.com/facebook/fbthrift/thrift/lib/go/thrift

Пакеты

Наименование

github.com/facebook/fbthrift

go
Затронутые версииВерсия исправления

< 0.31.1-0.20200311080807-483ed864d69f

0.31.1-0.20200311080807-483ed864d69f

EPSS

Процентиль: 69%
0.00615
Низкий

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.

CVSS3: 7.5
redhat
почти 6 лет назад

Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.

CVSS3: 7.5
nvd
почти 6 лет назад

Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.

EPSS

Процентиль: 69%
0.00615
Низкий

7.5 High

CVSS3

Дефекты

CWE-770