Apache Thrift
cpe:2.3:a:apache:thrift:*:*:*:*:*:*:*
- < 0.23.0
A vulnerability in the Apache Thrift c_glib language bindings prior to version 0.23.0 allows specially crafted requests to crash a Thrift server. This crash occurs with a clean but fatal 'free(): invalid pointer' error message, indicating a mismatch in memory management routines.
Exploitation of this vulnerability causes a denial-of-service condition by crashing the Thrift server with an invalid pointer error.
Users are advised to upgrade to Apache Thrift version 0.23.0 or later, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.