CVE-2019-0205

EUVD-2022-5184
In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings.
Infinite Loop
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 67%
Affected Products (NVD)
VendorProductVersion
apachethrift
𝑥
≤ 0.12.0
redhatjboss_enterprise_application_platform
7.2.0
oraclecommunications_cloud_native_core_network_slice_selection_function
1.2.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
thrift
bookworm
0.17.0-2
fixed
bullseye
0.13.0-6
fixed
buster
no-dsa
sid
0.19.0-2.1
fixed
trixie
0.19.0-2.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
thrift
bionic
dne
disco
dne
eoan
ignored
focal
not-affected
trusty
dne
xenial
dne
References