CVE-2015-3254

The client libraries in Apache Thrift before 0.9.3 might allow remote authenticated users to cause a denial of service (infinite recursion) via vectors involving the skip function.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:thrift:*:*:*:*:*:*:*:*

History

13 Feb 2023, 00:48

Type Values Removed Values Added
References
  • {'url': 'https://mail-archives.apache.org/mod_mbox/thrift-user/201512.mbox/%3CCANyrgvcjvEcjTVmaL+tVXCBm4o5G+1neu=MUubD9GbU85bO_Ew@mail.gmail.com%3E', 'name': '[thrift-user] 20151210 Re: [NOTICE]: Apache Thrift Security Vulnerability CVE-2015-1774', 'tags': ['Mailing List', 'Vendor Advisory'], 'refsource': 'MLIST'}
  • (MISC) https://mail-archives.apache.org/mod_mbox/thrift-user/201512.mbox/%3CCANyrgvcjvEcjTVmaL+tVXCBm4o5G+1neu=MUubD9GbU85bO_Ew%40mail.gmail.com%3E -

Information

Published : 2017-06-16 22:29

Updated : 2023-12-10 12:15


NVD link : CVE-2015-3254

Mitre link : CVE-2015-3254

CVE.ORG link : CVE-2015-3254


JSON object : View

Products Affected

apache

  • thrift
CWE
CWE-20

Improper Input Validation