First published: Mon May 06 2019(Updated: )
Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.03.04.00.
Credit: cve-assign@fb.com cve-assign@fb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Facebook Thrift | <2019.03.04.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3564 is a vulnerability that affects Go Facebook Thrift servers and could potentially lead to denial of service.
CVE-2019-3564 affects Facebook Thrift servers by allowing malicious clients to send short messages that could take a long time for the server to parse, potentially leading to denial of service.
The severity of CVE-2019-3564 is high with a CVSS score of 7.5.
To fix CVE-2019-3564, update Facebook Thrift to version 0.31.1-0.20190225164308-c461c1bd1a3e or later.
You can find more information about CVE-2019-3564 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-3564), [GitHub](https://github.com/facebook/fbthrift/commit/c461c1bd1a3e130b181aa9c854da3030cd4b5156), [Apache Mailing List](https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26@%3Ccommits.pulsar.apache.org%3E).