The client libraries in Apache Thrift before 0.9.3 might allow remote authenticated users to cause a denial of service (infinite recursion) via vectors involving the skip function.
References
| Link | Resource |
|---|---|
| https://mail-archives.apache.org/mod_mbox/thrift-user/201512.mbox/%3CCANyrgvcjvEcjTVmaL+tVXCBm4o5G+1neu=MUubD9GbU85bO_Ew@mail.gmail.com%3E | Mailing List Vendor Advisory |
| https://issues.apache.org/jira/browse/THRIFT-3231 | Issue Tracking Patch Vendor Advisory |
| http://grokbase.com/t/thrift/user/15c2tss3td/notice-apache-thrift-security-vulnerability-cve-2015-1774 | Mailing List Third Party Advisory |
| http://www.securityfocus.com/bid/99112 | |
| https://access.redhat.com/errata/RHSA-2017:3115 | |
| https://access.redhat.com/errata/RHSA-2017:2477 |
Configurations
Information
Published : 2017-06-16 22:29
Updated : 2018-01-05 02:30
NVD link : CVE-2015-3254
Mitre link : CVE-2015-3254
JSON object : View
Products Affected
apache
- thrift
CWE
CWE-20
Improper Input Validation
