Denial of Service Vulnerability in Facebook Thrift Legacy C++ Servers
CVE-2019-3565

7.5HIGH

Key Information:

Vendor

Facebook

Vendor
CVE Published:
6 May 2019

What is CVE-2019-3565?

The vulnerability in Facebook Thrift affects legacy C++ servers using cpp instead of cpp2, allowing malicious clients to exploit the system. When these servers receive messages containing container fields of unknown type, they fail to generate an error response. This flaw enables an attacker to send short, malformed messages that prolong server parsing times, potentially leading to a disruption of service. The affected versions of Facebook Thrift should be updated to at least v2019.05.06.00 to mitigate this risk.

Affected Version(s)

Facebook Thrift v2019.05.06.00

Facebook Thrift < unspecified

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2019-3565 : Denial of Service Vulnerability in Facebook Thrift Legacy C++ Servers