Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.03.04.00.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "0.13.0-2build2", "binary_name": "golang-thrift-dev" }, { "binary_version": "0.13.0-2build2", "binary_name": "libthrift-0.13.0" }, { "binary_version": "0.13.0-2build2", "binary_name": "libthrift-0.13.0-dbgsym" }, { "binary_version": "0.13.0-2build2", "binary_name": "libthrift-c-glib-dev" }, { "binary_version": "0.13.0-2build2", "binary_name": "libthrift-c-glib0" }, { "binary_version": "0.13.0-2build2", "binary_name": "libthrift-c-glib0-dbgsym" }, { "binary_version": "0.13.0-2build2", "binary_name": "libthrift-dev" }, { "binary_version": "0.13.0-2build2", "binary_name": "libthrift-perl" }, { "binary_version": "0.13.0-2build2", "binary_name": "php-thrift" }, { "binary_version": "0.13.0-2build2", "binary_name": "php-thrift-dbgsym" }, { "binary_version": "0.13.0-2build2", "binary_name": "python3-thrift" }, { "binary_version": "0.13.0-2build2", "binary_name": "python3-thrift-dbg" }, { "binary_version": "0.13.0-2build2", "binary_name": "thrift-compiler" }, { "binary_version": "0.13.0-2build2", "binary_name": "thrift-compiler-dbgsym" } ] }