Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.03.04.00.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_name": "golang-thrift-dev", "binary_version": "0.13.0-2build2" }, { "binary_name": "libthrift-0.13.0", "binary_version": "0.13.0-2build2" }, { "binary_name": "libthrift-0.13.0-dbgsym", "binary_version": "0.13.0-2build2" }, { "binary_name": "libthrift-c-glib-dev", "binary_version": "0.13.0-2build2" }, { "binary_name": "libthrift-c-glib0", "binary_version": "0.13.0-2build2" }, { "binary_name": "libthrift-c-glib0-dbgsym", "binary_version": "0.13.0-2build2" }, { "binary_name": "libthrift-dev", "binary_version": "0.13.0-2build2" }, { "binary_name": "libthrift-perl", "binary_version": "0.13.0-2build2" }, { "binary_name": "php-thrift", "binary_version": "0.13.0-2build2" }, { "binary_name": "php-thrift-dbgsym", "binary_version": "0.13.0-2build2" }, { "binary_name": "python3-thrift", "binary_version": "0.13.0-2build2" }, { "binary_name": "python3-thrift-dbg", "binary_version": "0.13.0-2build2" }, { "binary_name": "thrift-compiler", "binary_version": "0.13.0-2build2" }, { "binary_name": "thrift-compiler-dbgsym", "binary_version": "0.13.0-2build2" } ] }