A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 priority settings (specifically a circular dependency). This affects Proxygen prior to v2018.12.31.00.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "230449712156875099939158691282102359183", "54119929643809062252837333428365008268", "292891572538531077032530744604641686809" ] }, "signature_version": "v1", "signature_type": "Line", "source": "https://github.com/facebook/proxygen/commit/52cf331743ebd74194d6343a6c2ec52bb917c982", "id": "CVE-2018-6346-7b55a99e", "deprecated": false, "target": { "file": "proxygen/lib/http/codec/test/HTTP2CodecTest.cpp" } }, { "digest": { "threshold": 0.9, "line_hashes": [ "109284575450411577558246509559829908367", "115774218398046309736763532495824461470", "251527013847998687291701768407714357881", "54870410458949364531686023674384671471", "52328284539631915705417246728720244181", "326682915501515019234260919841384479428", "202534842530640227950026360856796760100", "23628784581736665657687667405288448954", "175090869773157792881747427134670709645", "159343007607272510029086856096607231200", "42335686558035738251676705302118114583", "66604707197353220536544647641041647057", "239958411686677169619042858286317939796", "112787413633313013524610953564690434451", "126947835366011784060365453870468503202", "291666100022110467297773819106936447504", "204967597786252806091899031685854123537" ] }, "signature_version": "v1", "signature_type": "Line", "source": "https://github.com/facebook/proxygen/commit/52cf331743ebd74194d6343a6c2ec52bb917c982", "id": "CVE-2018-6346-b9215fd3", "deprecated": false, "target": { "file": "proxygen/lib/http/codec/HTTP2Codec.cpp" } } ] }