CVE-2019-11937: High severity facebook mcrouter vulnerability
Published Dec 4, 2019
·Updated
In Mcrouter prior to v0.41.0, a large struct input provided to the Carbon protocol reader could result in stack exhaustion and denial of service.
Affected Software
1 affected component
Facebook Mcrouter<0.41.0
Remediation
Event History
Dec 4, 2019
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-11937?
CVE-2019-11937 is classified as a denial of service vulnerability.
2
How do I fix CVE-2019-11937?
To remediate CVE-2019-11937, upgrade Mcrouter to version 0.41.0 or later.
3
What causes CVE-2019-11937?
CVE-2019-11937 is caused by a large struct input that leads to stack exhaustion in the Carbon protocol reader.
4
What versions of Mcrouter are affected by CVE-2019-11937?
Mcrouter versions prior to 0.41.0 are affected by CVE-2019-11937.
5
Is CVE-2019-11937 related to security risks in Mcrouter?
Yes, CVE-2019-11937 poses security risks due to its potential to cause a denial of service.