In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
|
History
21 Nov 2024, 04:16
Type | Values Removed | Values Added |
---|---|---|
References | () http://mail-archives.apache.org/mod_mbox/thrift-dev/201910.mbox/%3C277A46CA87494176B1BBCF5D72624A2A%40HAGGIS%3E - Mailing List, Vendor Advisory | |
References | () https://access.redhat.com/errata/RHSA-2020:0804 - Third Party Advisory | |
References | () https://access.redhat.com/errata/RHSA-2020:0805 - Third Party Advisory | |
References | () https://access.redhat.com/errata/RHSA-2020:0806 - Third Party Advisory | |
References | () https://access.redhat.com/errata/RHSA-2020:0811 - Third Party Advisory | |
References | () https://lists.apache.org/thread.html/r2832722c31d78bef7526e2c701ba4b046736e4c851473194a247392f%40%3Ccommits.pulsar.apache.org%3E - | |
References | () https://lists.apache.org/thread.html/r36581cc7047f007dd6aadbdd34e18545ec2c1eb7ccdae6dd47a877a9%40%3Ccommits.pulsar.apache.org%3E - | |
References | () https://lists.apache.org/thread.html/r55609613abab203a1f2c1f3de050b63ae8f5c4a024df0d848d6915ff%40%3Ccommits.pulsar.apache.org%3E - | |
References | () https://lists.apache.org/thread.html/rab740e5c70424ef79fd095a4b076e752109aeee41c4256c2e5e5e142%40%3Ccommits.pulsar.apache.org%3E - | |
References | () https://security.gentoo.org/glsa/202107-32 - Third Party Advisory | |
References | () https://www.oracle.com//security-alerts/cpujul2021.html - Patch, Third Party Advisory |
20 Jul 2021, 23:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
07 Jun 2021, 15:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2019-10-29 19:15
Updated : 2024-11-21 04:16
NVD link : CVE-2019-0210
Mitre link : CVE-2019-0210
CVE.ORG link : CVE-2019-0210
JSON object : View
Products Affected
redhat
- enterprise_linux_server
- jboss_enterprise_application_platform
apache
- thrift
oracle
- communications_cloud_native_core_network_slice_selection_function
CWE
CWE-125
Out-of-bounds Read