VDB
Sign up
HIGH7.5

GHSA-w3r9-r9w7-8h48

Golang Facebook Thrift servers vulnerable to denial of service

Quick fix

GHSA-w3r9-r9w7-8h48 — github.com/facebook/fbthrift: upgrade to the fixed version with the command below.

go get github.com/facebook/fbthrift@v0.31.1-0.20200311080807-483ed864d69f

Details

Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.

### Specific Go Packages Affected github.com/facebook/fbthrift/thrift/lib/go/thrift

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/facebook/fbthrift
Introduced in: 0Fixed in: 0.31.1-0.20200311080807-483ed864d69f
Fixgo get github.com/facebook/fbthrift@v0.31.1-0.20200311080807-483ed864d69f

References