An improperly performed length calculation on a buffer in PlaintextRecordLayer could lead to an infinite loop and denial-of-service based on user input. This issue affected versions of fizz prior to v2019.03.04.00.
References
Configurations
History
21 Nov 2024, 04:42
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/172836/polkit-Authentication-Bypass.html - | |
References | () http://packetstormsecurity.com/files/172846/Facebook-Fizz-Denial-Of-Service.html - | |
References | () https://github.com/facebookincubator/fizz/commit/40bbb161e72fb609608d53b9d64c56bb961a6ee2 - Patch, Third Party Advisory |
07 Nov 2023, 03:09
Type | Values Removed | Values Added |
---|---|---|
References |
|
12 Jun 2023, 07:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2019-04-29 16:29
Updated : 2024-11-21 04:42
NVD link : CVE-2019-3560
Mitre link : CVE-2019-3560
CVE.ORG link : CVE-2019-3560
JSON object : View
Products Affected
- fizz