Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.03.04.00.
{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2019.03.04.00"
}
],
"source": [
"CPE_FIELD",
"REFERENCES"
],
"cpe": "cpe:2.3:a:facebook:thrift:*:*:*:*:*:*:*:*"
}