CVE-2019-11939: High severity thrift vulnerability
Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-11939?
The severity of CVE-2019-11939 is high.
How does CVE-2019-11939 affect Golang Facebook Thrift servers?
CVE-2019-11939 allows malicious clients to send short messages that result in a large memory allocation, potentially leading to denial of service.
Which software versions are affected by CVE-2019-11939?
Versions up to and excluding 0.31.1-0.20200311080807-483ed864d69f of GitHub.com/facebook/fbthrift and versions up to and excluding 2020.03.16.00 of Facebook Thrift are affected by CVE-2019-11939.
How can I fix CVE-2019-11939?
To fix CVE-2019-11939, update your Golang Facebook Thrift servers to version 0.31.1-0.20200311080807-483ed864d69f or later.
What is the CWE ID for CVE-2019-11939?
The CWE ID for CVE-2019-11939 is 770.