Integer Overflow Vulnerability in Facebook HipHop Virtual Machine
CVE-2014-6228

Currently unrated

Key Information:

Vendor

Facebook

Vendor
CVE Published:
28 December 2014

What is CVE-2014-6228?

An integer overflow vulnerability exists in the string_chunk_split function within Facebook's HipHop Virtual Machine (HHVM) prior to version 3.3.0. Remote attackers can exploit this flaw by sending specially crafted arguments to the chunk_split function, potentially leading to a denial of service condition, resulting in application crashes or causing other unforeseen impacts on system operations.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.