Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

SSL:FACEBOOK-FIZZ-TLS13-IO-DOS

Severity

Major

Recommended

Yes

Recommended Action

Drop

Category

SSL

Keywords

Facebook Fizz TLS 1.3 Early Data Integer Overflow Denial of Service

Release Date

2019/06/04

Update Number

3177

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

SSL: Facebook Fizz TLS 1.3 Early Data Integer Overflow Denial of Service


This signature detects attempts to exploit a known vulnerability against Facebook Fizz. A successful attack can result in a denial-of-service condition.

Extended Description

An improperly performed length calculation on a buffer in PlaintextRecordLayer could lead to an infinite loop and denial-of-service based on user input. This issue affected versions of fizz prior to v2019.03.04.00.

Affected Products

  • Facebook fizz 2018.09.24.00
  • Facebook fizz 2018.10.01.00
  • Facebook fizz 2018.10.08.00
  • Facebook fizz 2018.10.15.00
  • Facebook fizz 2018.10.22.00
  • Facebook fizz 2018.10.29.00
  • Facebook fizz 2018.11.05.00
  • Facebook fizz 2018.11.12.00
  • Facebook fizz 2018.11.19.00
  • Facebook fizz 2018.11.26.00
  • Facebook fizz 2018.12.03.00
  • Facebook fizz 2018.12.10.00
  • Facebook fizz 2018.12.17.00
  • Facebook fizz 2018.12.24.00
  • Facebook fizz 2018.12.31.00
  • Facebook fizz 2019.01.07.00
  • Facebook fizz 2019.01.14.00
  • Facebook fizz 2019.01.21.00
  • Facebook fizz 2019.01.28.00
  • Facebook fizz 2019.02.04.00
  • Facebook fizz 2019.02.11.00
  • Facebook fizz 2019.02.18.00
  • Facebook fizz 2019.02.25.00

References

  • CVE: CVE-2019-3560
  • URL: https://lgtm.com/blog/facebook_fizz_CVE-2019-3560
  • URL: https://threatpost.com/dos-bug-facebook-fizz-tls/143086/

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out