« Volver al listado

CVE-2019-11934

Estado: ModificadaCrítica (9.8)—

Improper handling of close_notify alerts can result in an out-of-bounds read in AsyncSSLSocket. This issue affects folly prior to v2019.11.04.00.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-11934",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve-assign@fb.com",
      "affectedData": [
        {
          "vendor": "Facebook",
          "product": "folly",
          "versions": [
            {
              "status": "affected",
              "version": "v2019.11.04.00"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "v2019.11.04.00",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-12-04T17:16:43.180",
  "references": [
    {
      "url": "https://github.com/facebook/folly/commit/c321eb588909646c15aefde035fd3133ba32cdee",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "cve-assign@fb.com"
    },
    {
      "url": "https://www.facebook.com/security/advisories/cve-2019-11934",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve-assign@fb.com"
    },
    {
      "url": "https://github.com/facebook/folly/commit/c321eb588909646c15aefde035fd3133ba32cdee",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.facebook.com/security/advisories/cve-2019-11934",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-125"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper handling of close_notify alerts can result in an out-of-bounds read in AsyncSSLSocket. This issue affects folly prior to v2019.11.04.00."
    },
    {
      "lang": "es",
      "value": "Un manejo inapropiado de las alertas de close_notify puede resultar en una lectura fuera de límites en AsyncSSLSocket. Este problema afecta a folly anterior a la versión v2019.11.04.00."
    }
  ],
  "lastModified": "2026-06-17T02:13:51.947",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:facebook:folly:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "736329E0-780E-46BE-9B50-A71072D1C6DC",
              "versionEndExcluding": "2019.11.04.00"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve-assign@fb.com"
}