PT-2021-10264 · Facebook · Hhvm

Jjergus

·

Published

2021-03-11

·

Updated

2021-03-18

·

CVE-2020-1899

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: HHVM versions prior to 4.32.3 HHVM versions 4.33.0 through 4.62.0
Description: The unserialize() function has a type code, "S", which was meant to be supported only for APC serialization. This type code allowed arbitrary memory addresses to be accessed as if they were static StringData objects.
Recommendations: For HHVM versions prior to 4.32.3, update to version 4.32.3 or later. For HHVM versions 4.33.0 through 4.62.0, update to a version outside of this range, as these versions are affected by the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability for versions 4.57.0, 4.58.0, 4.58.1, 4.59.0, 4.60.0, 4.61.0, 4.62.0.

Fix

Untrusted Pointer Dereference

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-1899

Affected Products

Hhvm