Updated thrift/golang-github-apache-thrift packages fix security vulnerability
Publication date: 23 Dec 2021Modification date: 23 Dec 2021
Type: security
Affected Mageia releases : 8
CVE: CVE-2020-13949
Description
Malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.
References
SRPMS
8/core
- thrift-0.14.0-1.mga8
- golang-github-apache-thrift-0.14.0-1.mga8