CVE-2019-0205

In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings.
Infinite Loop
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 66%
VendorProductVersion
apachethrift
𝑥
≤ 0.12.0
redhatjboss_enterprise_application_platform
7.2.0
oraclecommunications_cloud_native_core_network_slice_selection_function
1.2.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
thrift
bullseye
0.13.0-6
fixed
buster
no-dsa
bookworm
0.17.0-2
fixed
sid
0.19.0-2.1
fixed
trixie
0.19.0-2.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
thrift
focal
not-affected
eoan
ignored
disco
dne
bionic
dne
xenial
dne
trusty
dne
References