mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-28 01:04:30 +00:00
945 B
945 B
CVE-2019-11924
Description
A peer could send empty handshake fragments containing only padding which would be kept in memory until a full handshake was received, resulting in memory exhaustion. This issue affects versions v2019.01.28.00 and above of fizz, until v2019.08.05.00.
POC
Reference
- https://www.facebook.com/security/advisories/cve-2019-11924
- https://www.facebook.com/security/advisories/cve-2019-11924