7.5

CVE-2019-0210

In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Thrift Version >= 0.9.3 <= 0.12.0
Redhat ≫ Jboss Enterprise Application Platform Version 7.2.0
   Redhat ≫ Enterprise Linux Server Version 6.0
   Redhat ≫ Enterprise Linux Server Version 7.0
   Redhat ≫ Enterprise Linux Server Version 8.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.85% 0.933
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

https://www.oracle.com//security-alerts/cpujul2021.html
Patch
Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0804
Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0805
Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0806
Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0811
Third Party Advisory
https://lists.apache.org/thread.html/r2832722c31d78bef7526e2c701ba4b046736e4c851473194a247392f%40%3Ccommits.pulsar.apache.org%3E
https://lists.apache.org/thread.html/r36581cc7047f007dd6aadbdd34e18545ec2c1eb7ccdae6dd47a877a9%40%3Ccommits.pulsar.apache.org%3E
https://lists.apache.org/thread.html/r55609613abab203a1f2c1f3de050b63ae8f5c4a024df0d848d6915ff%40%3Ccommits.pulsar.apache.org%3E
https://lists.apache.org/thread.html/rab740e5c70424ef79fd095a4b076e752109aeee41c4256c2e5e5e142%40%3Ccommits.pulsar.apache.org%3E
https://security.gentoo.org/glsa/202107-32
Third Party Advisory
http://mail-archives.apache.org/mod_mbox/thrift-dev/201910.mbox/%3C277A46CA87494176B1BBCF5D72624A2A%40HAGGIS%3E
Vendor Advisory
Mailing List