Candidate: CVE-2019-3564 PublicDate: 2019-05-06 16:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3564 https://github.com/facebook/fbthrift/commit/c461c1bd1a3e130b181aa9c854da3030cd4b5156 https://www.facebook.com/security/advisories/cve-2019-3564 Description: Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.03.04.00. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_gitaly: upstream_gitaly: needs-triage precise/esm_gitaly: DNE trusty/esm_gitaly: DNE xenial_gitaly: DNE bionic_gitaly: DNE cosmic_gitaly: ignored (reached end-of-life) disco_gitaly: DNE eoan_gitaly: DNE focal_gitaly: DNE groovy_gitaly: DNE hirsute_gitaly: DNE impish_gitaly: DNE jammy_gitaly: DNE devel_gitaly: DNE Patches_hhvm: upstream_hhvm: needs-triage precise/esm_hhvm: DNE trusty/esm_hhvm: DNE xenial_hhvm: ignored (end of standard support, was needs-triage) bionic_hhvm: needs-triage cosmic_hhvm: DNE disco_hhvm: DNE eoan_hhvm: DNE focal_hhvm: DNE groovy_hhvm: DNE hirsute_hhvm: DNE impish_hhvm: DNE jammy_hhvm: DNE devel_hhvm: DNE