First published: Tue Jan 15 2019(Updated: )
Wangle's AcceptRoutingHandler incorrectly casts a socket when accepting a TLS 1.3 connection, leading to a potential denial of service attack against systems accepting such connections. This affects versions of Wangle prior to v2019.01.14.00
Credit: cve-assign@fb.com cve-assign@fb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Facebook Wangle | <2019.01.14.00 | |
<2019.01.14.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3554 is classified as a denial of service vulnerability.
To fix CVE-2019-3554, upgrade Wangle to version 2019.01.14.00 or later.
CVE-2019-3554 affects all versions of Facebook Wangle prior to 2019.01.14.00.
Exploiting CVE-2019-3554 can lead to a denial of service against systems accepting TLS 1.3 connections.
Yes, CVE-2019-3554 specifically affects the handling of TLS 1.3 connections.