An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 when parsing malformed binary content in Structured HTTP Headers. This issue affects versions of proxygen prior to v2019.07.22.00.
References
Link | Resource |
---|---|
https://www.facebook.com/security/advisories/cve-2019-11921 | Third Party Advisory |
https://github.com/facebook/proxygen/commit/2f07985bef9fbae124cc63e5c0272e32da4fdaec | Patch Third Party Advisory |
Configurations
Information
Published : 2019-07-25 14:15
Updated : 2019-08-02 13:43
NVD link : CVE-2019-11921
Mitre link : CVE-2019-11921
JSON object : View
CWE
CWE-787
Out-of-bounds Write
Products Affected
- proxygen