CVE-2019-11924: High severity facebook fizz vulnerability
Published Aug 20, 2019
·Updated
A peer could send empty handshake fragments containing only padding which would be kept in memory until a full handshake was received, resulting in memory exhaustion. This issue affects versions v2019.01.28.00 and above of fizz, until v2019.08.05.00.
Affected Software
1 affected component
Facebook Fizz>=2019.01.28.00<=2019.08.05.00
Remediation
Event History
Aug 20, 2019
CVE Published
via MITRE·07:32 PM
Data Sourced
via MITRE·07:32 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-11924?
The severity of CVE-2019-11924 is high with a score of 7.5.
2
How does CVE-2019-11924 affect Facebook Fizz?
CVE-2019-11924 affects versions v2019.01.28.00 and above of Facebook Fizz until v2019.08.05.00.
3
What is the impact of CVE-2019-11924?
CVE-2019-11924 can result in memory exhaustion due to empty handshake fragments containing only padding.
4
How can I fix CVE-2019-11924?
To fix CVE-2019-11924, update Facebook Fizz to version v2019.08.05.00 or above.
5
Where can I find more information about CVE-2019-11924?
More information about CVE-2019-11924 can be found in the Facebook Fizz security advisory.