First published: Mon May 06 2019(Updated: )
Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.05.06.00.
Credit: cve-assign@fb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Facebook Thrift | <2019.05.06.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-3565 is high with a severity value of 7.5.
CVE-2019-3565 affects legacy C++ Facebook Thrift servers (using cpp instead of cpp2) and can potentially lead to denial of service.
Software versions up to (but not including) 2019.05.06.00 of Facebook Thrift are affected by CVE-2019-3565.
Malicious clients can send short messages with containers of fields of unknown type, which can cause the server to take a long time to parse and potentially lead to denial of service.
You can find more information about CVE-2019-3565 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/108280), [GitHub](https://github.com/facebook/fbthrift/commit/01686e15ec77ccb4d49a77d5bce3a01601e54d64), [Apache Mailing List](https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26@%3Ccommits.pulsar.apache.org%3E).