Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.
{
"cpe": "cpe:2.3:a:facebook:thrift:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2020.03.16.00"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}