CVE Database
/

CVE-2018-6343

Back to search

CVE-2018-6343

Published: Dec 31, 2018

Modified: May 6, 2025

PUBLISHED

Description

Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of service issue when parsing a Certificate/CertificateRequest HTTP2 Frame over a fizz (TLS 1.3) transport. This issue affects Proxygen releases starting from v2018.10.29.00 until the fix in v2018.11.19.00.

VendorProductVersions

Facebook

Proxygen

affected
v2018.11.19.00
affected
v2018.10.29.00 - < unspecified
unaffected
unspecified - < v2018.10.29.00

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now