Medium severity6.5NVD Advisory· Published Jun 16, 2017· Updated May 13, 2026
CVE-2015-3254
CVE-2015-3254
Description
The client libraries in Apache Thrift before 0.9.3 might allow remote authenticated users to cause a denial of service (infinite recursion) via vectors involving the skip function.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- issues.apache.org/jira/browse/THRIFT-3231nvdIssue TrackingPatchVendor Advisory
- grokbase.com/t/thrift/user/15c2tss3td/notice-apache-thrift-security-vulnerability-cve-2015-1774nvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/99112nvd
- access.redhat.com/errata/RHSA-2017:2477nvd
- access.redhat.com/errata/RHSA-2017:3115nvd
- mail-archives.apache.org/mod_mbox/thrift-user/201512.mbox/%3CCANyrgvcjvEcjTVmaL+tVXCBm4o5G+1neu=MUubD9GbU85bO_Ew%40mail.gmail.com%3Envd
News mentions
0No linked articles in our index yet.