CVE-2019-3560 is a denial-of-service vulnerability affecting Facebook Fizz versions prior to v2019.03.04.00. An improper length calculation in the PlaintextRecordLayer could lead to an infinite loop when processing user input. This vulnerability has a CVSS score of 7.5 (HIGH), indicating it can be exploited remotely with low complexity, resulting in a complete loss of availability. There is no public exploit code available, it is not listed in CISA's KEV catalog, and community discussion and media coverage are minimal, suggesting it is not actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2019.03.04.00CPE matchmatch criteria | cpe:2.3:a:facebook:fizz:*:*:*:*:*:*:*:* | ||
< v2019.03.04.00CPE match | cpe:2.3:a:facebook:fizz:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.