CVE-2019-3554: Medium severity facebook wangle vulnerability
Published Jan 15, 2019
·Updated
Wangle's AcceptRoutingHandler incorrectly casts a socket when accepting a TLS 1.3 connection, leading to a potential denial of service attack against systems accepting such connections. This affects versions of Wangle prior to v2019.01.14.00
Affected Software
1 affected component
Facebook Wangle<2019.01.14.00
Remediation
Event History
Jan 15, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Data Sourced
via NVD·10:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-3554?
CVE-2019-3554 is classified as a denial of service vulnerability.
2
How do I fix CVE-2019-3554?
To fix CVE-2019-3554, upgrade Wangle to version 2019.01.14.00 or later.
3
What software is affected by CVE-2019-3554?
CVE-2019-3554 affects all versions of Facebook Wangle prior to 2019.01.14.00.
4
What is the impact of exploiting CVE-2019-3554?
Exploiting CVE-2019-3554 can lead to a denial of service against systems accepting TLS 1.3 connections.
5
Is CVE-2019-3554 related to TLS 1.3 connections?
Yes, CVE-2019-3554 specifically affects the handling of TLS 1.3 connections.