CVE-2020-1918

In-memory file operations (ie: using fopen on a data URI) did not properly restrict negative seeking, allowing for the reading of memory prior to the in-memory buffer. This issue affects HHVM versions prior to 4.56.3, all versions between 4.57.0 and 4.80.1, all versions between 4.81.0 and 4.93.1, and versions 4.94.0, 4.95.0, 4.96.0, 4.97.0, 4.98.0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.94.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.95.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.96.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.97.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.98.0:*:*:*:*:*:*:*

History

21 Nov 2024, 05:11

Type Values Removed Values Added
References () https://github.com/facebook/hhvm/commit/08193b7f0cd3910256e00d599f0f3eb2519c44ca - Patch, Third Party Advisory () https://github.com/facebook/hhvm/commit/08193b7f0cd3910256e00d599f0f3eb2519c44ca - Patch, Third Party Advisory
References () https://hhvm.com/blog/2021/02/25/security-update.html - Release Notes, Vendor Advisory () https://hhvm.com/blog/2021/02/25/security-update.html - Release Notes, Vendor Advisory

Information

Published : 2021-03-10 16:15

Updated : 2024-11-21 05:11


NVD link : CVE-2020-1918

Mitre link : CVE-2020-1918

CVE.ORG link : CVE-2020-1918


JSON object : View

Products Affected

facebook

  • hhvm
CWE
CWE-127

Buffer Under-read

CWE-125

Out-of-bounds Read