Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-11939

Опубликовано: 18 мар. 2020
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:facebook:thrift:*:*:*:*:*:*:*:*
Версия до 2020.03.16.00 (исключая)

EPSS

Процентиль: 73%
0.01557
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-770
CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.

CVSS3: 7.5
redhat
больше 6 лет назад

Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.

msrc
21 день назад

Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.

CVSS3: 7.5
github
больше 4 лет назад

Golang Facebook Thrift servers vulnerable to denial of service

EPSS

Процентиль: 73%
0.01557
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-770
CWE-770