CVE Vulnerabilities

CVE-2019-3559

Excessive Iteration

Published: May 06, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.02.18.00.

Weakness

The product performs an iteration or loop without sufficiently limiting the number of times that the loop is executed.

Affected Software

NameVendorStart VersionEnd Version
ThriftFacebook*2019.02.18.00 (excluding)
HhvmUbuntubionic*
HhvmUbuntuxenial*
Libthrift-javaUbuntubionic*
Libthrift-javaUbuntucosmic*
Libthrift-javaUbuntuesm-apps/bionic*
Libthrift-javaUbuntuesm-apps/xenial*
Libthrift-javaUbuntuxenial*

References