In Mcrouter prior to v0.41.0, a large struct input provided to the Carbon protocol reader could result in stack exhaustion and denial of service.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-11937.json"
[
{
"deprecated": false,
"source": "https://github.com/facebook/mcrouter/commit/97e033b3bb0cb16b61bf49f0dc7f311a3e0edd1b",
"signature_type": "Line",
"target": {
"file": "mcrouter/lib/carbon/CarbonProtocolReader.cpp"
},
"id": "CVE-2019-11937-754e2a1b",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"65161515500616568558656657028519200949",
"211871914796959863846934910901354094903",
"167072776203480378383959684283413084932",
"287441299355480581747519674051041422660",
"5928327514337020991552201001823937487",
"194894419827936238695643242947369075622",
"321974394087091680584651102824025550378",
"211488159856352772860105901494483197795",
"187480002121884995759788625953718996382",
"200497279708899711979223314648232423331",
"324038733964501136469472308180816719353",
"171330923685853089644337207322548552352",
"82713770421532349676075287601689598486",
"3550457628982714179147233303082124235"
]
}
},
{
"deprecated": false,
"source": "https://github.com/facebook/mcrouter/commit/97e033b3bb0cb16b61bf49f0dc7f311a3e0edd1b",
"signature_type": "Function",
"target": {
"file": "mcrouter/lib/carbon/CarbonProtocolReader.cpp",
"function": "CarbonProtocolReader::skip"
},
"id": "CVE-2019-11937-8b21346f",
"signature_version": "v1",
"digest": {
"length": 967.0,
"function_hash": "338708658738725844228037726447850122146"
}
},
{
"deprecated": false,
"source": "https://github.com/facebook/mcrouter/commit/97e033b3bb0cb16b61bf49f0dc7f311a3e0edd1b",
"signature_type": "Line",
"target": {
"file": "mcrouter/lib/carbon/CarbonProtocolReader.h"
},
"id": "CVE-2019-11937-fb898708",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"194489831403648663238481715541015036153",
"299405957060261401258185212596721711662",
"333748399651933197211965056899606848901",
"120521487789386056350350313606559228989",
"104720807227338357736598230379988928171"
]
}
}
]