CVE-2019-3560
HIGHFacebook Fizz < 2019.03.04.00 - Denial of Service via PlaintextRecordLayer Buffer Length Calculation
Title source: llmDescription
An improperly performed length calculation on a buffer in PlaintextRecordLayer could lead to an infinite loop and denial-of-service based on user input. This issue affected versions of fizz prior to v2019.03.04.00.
References (3)
Core 3
Core References
Patch, Third Party Advisory
https://github.com/facebookincubator/fizz/commit/40bbb161e72fb609608d53b9d64c56bb961a6ee2
Exploit, Third Party Advisory
http://packetstormsecurity.com/files/172836/polkit-Authentication-Bypass.html
Exploit, Third Party Advisory
http://packetstormsecurity.com/files/172846/Facebook-Fizz-Denial-Of-Service.html
Scores
CVSS v3
7.5
EPSS
0.0242
EPSS Percentile
82.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-131
CWE-835
Status
published
Products (1)
facebook/fizz
< 2019.03.04.00
Published
Apr 29, 2019
Tracked Since
Feb 18, 2026