A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 priority settings (specifically a circular dependency). This affects Proxygen prior to v2018.12.31.00.
[
{
"signature_version": "v1",
"source": "https://github.com/facebook/proxygen/commit/52cf331743ebd74194d6343a6c2ec52bb917c982",
"signature_type": "Line",
"target": {
"file": "proxygen/lib/http/codec/test/HTTP2CodecTest.cpp"
},
"id": "CVE-2018-6346-7b55a99e",
"digest": {
"line_hashes": [
"230449712156875099939158691282102359183",
"54119929643809062252837333428365008268",
"292891572538531077032530744604641686809"
],
"threshold": 0.9
},
"deprecated": false
},
{
"signature_version": "v1",
"source": "https://github.com/facebook/proxygen/commit/52cf331743ebd74194d6343a6c2ec52bb917c982",
"signature_type": "Line",
"target": {
"file": "proxygen/lib/http/codec/HTTP2Codec.cpp"
},
"id": "CVE-2018-6346-b9215fd3",
"digest": {
"line_hashes": [
"109284575450411577558246509559829908367",
"115774218398046309736763532495824461470",
"251527013847998687291701768407714357881",
"54870410458949364531686023674384671471",
"52328284539631915705417246728720244181",
"326682915501515019234260919841384479428",
"202534842530640227950026360856796760100",
"23628784581736665657687667405288448954",
"175090869773157792881747427134670709645",
"159343007607272510029086856096607231200",
"42335686558035738251676705302118114583",
"66604707197353220536544647641041647057",
"239958411686677169619042858286317939796",
"112787413633313013524610953564690434451",
"126947835366011784060365453870468503202",
"291666100022110467297773819106936447504",
"204967597786252806091899031685854123537"
],
"threshold": 0.9
},
"deprecated": false
}
]