CVE-2019-11930

An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.28.0, and 4.28.1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.24.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.25.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.26.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.27.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.28.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.28.1:*:*:*:*:*:*:*

History

21 Nov 2024, 04:22

Type Values Removed Values Added
References () https://github.com/facebook/hhvm/commit/524d2e60cfe910406ec6109e4286d7edd545ab36 - Patch () https://github.com/facebook/hhvm/commit/524d2e60cfe910406ec6109e4286d7edd545ab36 - Patch
References () https://hhvm.com/blog/2019/10/28/security-update.html - Vendor Advisory () https://hhvm.com/blog/2019/10/28/security-update.html - Vendor Advisory
References () https://www.facebook.com/security/advisories/cve-2019-11930 - Vendor Advisory () https://www.facebook.com/security/advisories/cve-2019-11930 - Vendor Advisory

08 Feb 2024, 20:12

Type Values Removed Values Added
References (CONFIRM) https://www.facebook.com/security/advisories/cve-2019-11930 - Third Party Advisory (CONFIRM) https://www.facebook.com/security/advisories/cve-2019-11930 - Vendor Advisory

Information

Published : 2019-12-04 17:16

Updated : 2024-11-21 04:22


NVD link : CVE-2019-11930

Mitre link : CVE-2019-11930

CVE.ORG link : CVE-2019-11930


JSON object : View

Products Affected

facebook

  • hhvm
CWE
CWE-763

Release of Invalid Pointer or Reference