Denial of Service Vulnerability in Facebook Thrift by Facebook
CVE-2019-11938

7.5HIGH

Key Information:

Vendor

Facebook

Vendor
CVE Published:
10 March 2020

What is CVE-2019-11938?

A vulnerability in Facebook Thrift allows attackers to exploit the server's handling of messages with oversized container declarations. By sending short messages, malicious clients can trigger large memory allocations on the server, potentially leading to denial of service. This issue has been addressed in versions released after v2019.12.09.00, and it highlights the importance of input size validation to prevent resource exhaustion attacks.

Affected Version(s)

Facebook Thrift < unspecified

Facebook Thrift v2019.12.09.00

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2019-11938 : Denial of Service Vulnerability in Facebook Thrift by Facebook