Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift C++, Java, Go, netstd, Python and Delphi bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Access of Uninitialized Pointer vulnerability in Apache Thrift cglib bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Apache Thrift: PHP accelerator sizes a stack buffer from a wire-controlled string length
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: skip() does not apply the recursion limit (Python accelerator, PHP, Perl, Lua, Smalltalk, OCaml)
Apache Thrift: cglib multiplexed processor crashes on a message it cannot route
Apache Thrift: TFramedTransport and THeaderTransport re-enter Read once per frame that carries no payload (Go)
Apache Thrift: cglib readall spins when the underlying read returns 0
Apache Thrift: Perl FramedTransport reads and TLS socket writes re-slice the remaining buffer on every call (quadratic)
Apache Thrift: Perl servers end serve() when serving one connection fails
Apache Thrift: Ruby SimpleServer ends serve() on any non-Transport/Protocol exception
Apache Thrift: Lua TFramedTransport/THttpTransport re-slice the buffer on every read (quadratic)
Allocation of resources without limits or throttling vulnerability in Apache Thrift ruby bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Allocation of resources without limits or throttling, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Apache Thrift: PHP framed/memory/HTTP transports re-slice the buffer on every read (quadratic)
Allocation of resources without limits or throttling vulnerability in Apache Thrift dart bindings.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Apache Thrift: Node.js server.js ends the process on any per-connection error (+ two triggers)
Apache Thrift: Go THeaderTransport does not bound the inflated size of a ZLIB frame
Apache Thrift: Python TZlibTransport stops enforcing its decompressed-size limit once the limit is exactly used up
Apache Thrift: An exception escaping a libevent callback stops the D library's non-blocking server, allowing an unauthenticated remote attacker to deny service
Apache Thrift: PHP thriftprotocol accelerator dereferences a missing container-element spec
Apache Thrift: A truncated HTTP request stops the D library's server, allowing an unauthenticated remote attacker to deny service
Apache Thrift: Integer underflow in C++ THeaderTransport allows an unauthenticated remote peer to terminate a 32-bit process
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: Container element count not bounded by the bytes available
Apache Thrift: Lua THttpTransport:parseHeaders matches each header line with a backtracking pattern (quadratic)
Apache Thrift: nodejs web server: no error listener on an upgraded WebSocket connection
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java TSaslNonblockingServer.
This issue affects Apache Thrift: before 0.25.0.
Users are recommended to upgrade to version 0.25.0, which fixes the issue.
Apache Thrift: PHP TSimpleServer exits the whole process on any non-transport exception
Apache Thrift: Node.js TJSONProtocol uses a peer-declared container size as an unbounded loop bound
Apache Thrift: cglib generated struct readers have no recursion-depth guard (native stack exhaustion)
Apache Thrift: Java TSaslNonblockingServer Computation.run orphans a connection on a pre-auth parse error