An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 when parsing malformed binary content in Structured HTTP Headers. This issue affects versions of proxygen prior to v2019.07.22.00.
References
Link | Resource |
---|---|
https://github.com/facebook/proxygen/commit/2f07985bef9fbae124cc63e5c0272e32da4fdaec | Patch Third Party Advisory |
https://www.facebook.com/security/advisories/cve-2019-11921 | Third Party Advisory |
https://github.com/facebook/proxygen/commit/2f07985bef9fbae124cc63e5c0272e32da4fdaec | Patch Third Party Advisory |
https://www.facebook.com/security/advisories/cve-2019-11921 | Third Party Advisory |
Configurations
History
21 Nov 2024, 04:21
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/facebook/proxygen/commit/2f07985bef9fbae124cc63e5c0272e32da4fdaec - Patch, Third Party Advisory | |
References | () https://www.facebook.com/security/advisories/cve-2019-11921 - Third Party Advisory |
Information
Published : 2019-07-25 21:15
Updated : 2024-11-21 04:21
NVD link : CVE-2019-11921
Mitre link : CVE-2019-11921
CVE.ORG link : CVE-2019-11921
JSON object : View
Products Affected
- proxygen
CWE
CWE-787
Out-of-bounds Write