CVE-2019-11924
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/08/2019
Last modified:
24/08/2020
Description
A peer could send empty handshake fragments containing only padding which would be kept in memory until a full handshake was received, resulting in memory exhaustion. This issue affects versions v2019.01.28.00 and above of fizz, until v2019.08.05.00.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
7.80
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:facebook:fizz:*:*:*:*:*:*:*:* | 2019.01.28.00 (including) | 2019.08.05.00 (including) |
To consult the complete list of CPE names with products and versions, see this page



