CRLF Injection Vulnerability in Facebook HipHop Virtual Machine
CVE-2014-2208

Currently unrated

Key Information:

Vendor

Facebook

Vendor
CVE Published:
28 December 2014

What is CVE-2014-2208?

A CRLF injection vulnerability exists in the implementation of the LightProcess protocol in Facebook's HipHop Virtual Machine (HHVM) prior to version 2.4.2. This vulnerability enables remote attackers to inject newline characters into the input, allowing the possibility of arbitrary command execution. By strategically placing a newline character before the end of a string, an attacker could compromise the security model of applications relying on HHVM.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.